Skip to content

VibeCode Privacy Policy

This policy explains what data we collect and store when you use VibeCode, what we use it for, where it is sent, how long it is kept, and what you can do about it. It applies to the VibeCode desktop app, the VS Code extension, web Chat, the VibeCode API, and the VibeCode website. The service is operated by VibeCode, Jakarta ("we", "us").

Last updated:

Data we collect and store

This section lists only the data our systems actually store. We do not store the content of your conversations with models in our database, except for the web Chat history described below. How long each kind of data is kept is summarized in the section How long data is kept.

Sign-in account

You sign in with an email and password, or with a Google account, through Firebase Authentication, a Google service. Firebase stores, among other things, your UID (your account identifier) and email address, and our server receives both through your sign-in token on every request that needs an account. Passwords are managed by Firebase and never pass through VibeCode's servers.

Account profile in the desktop app and the VS Code extension

When you sign in through the desktop app or the VS Code extension, the app creates one profile document for your account in our Firebase database (Firestore). It contains your UID as the document name, your email, an old plan marker, and old usage counters together with the start of their period.

User list on our server

Our server stores your UID, the email address from your sign-in token, and the time your account was first seen (on your first chat or API request) in a user list that only an administrator can open. This list is used to run the service, for example to find an account when you ask for help or to change a subscription tier.

Credit, plans, and usage counters

For each account we store the Credit wallet balance, the subscription tier (Free, Pro, or Max) with the plan's expiry date, plan usage counters for the 5-hour and weekly windows, and daily request and search counters.

Payment transaction records

For each top-up or plan purchase we store one transaction record containing the transaction id, your UID, the base price, the total paid, the type (wallet or plan), the status, the time it was created, the time it expires, the time it finished, and a random key for opening that transaction's payment page. When the payment is confirmed, the record also holds the mutation id and the amount read from the payment portal, and the time at which our system recorded them. Your name, bank account number, e-wallet number, and card details are not part of this record. A payment that is read but does not match any transaction is kept as an unmatched-mutation record (mutation id, amount, time, and the reason it did not match) so an administrator can trace it and, if needed, assign it to the right account. Administrators also have a payment event log that keeps only the most recent events and contains, among other things, the mutation id, the transaction id, the UID, and the amount.

Web Chat history

Web Chat stores your conversation history on our server so it syncs across all your devices: the conversation title, your messages (including the content of text files and the images you attach), and the model's answers. The limits are 200 conversations per account, 8 MiB per conversation, and 50 MiB per account. The service opens this history only to the account that owns it. From the Chat page you can delete one conversation or your entire history, and download your entire history, at any time.

History on your device

Conversation history, agent memory, attachments, and settings in the desktop app and the VS Code extension are stored on your device, not on our server. The sign-in token and any model keys you enter in the app are stored encrypted using the operating system's secure storage (in the VS Code extension: VS Code's secret storage), and the app refuses to store them if that encryption is unavailable.

Data in your browser

The website stores data in your browser's storage (localStorage, sessionStorage, and IndexedDB): the Firebase sign-in session, a marker that you have signed in before and when the session started, the last model you picked in Chat, the code-example language tab in the API documentation, and a cache of the exchange rate and release information. If you choose Stay signed in on this device (checked by default), your sign-in session is kept for up to 30 days or until you press Sign out, so turn that option off on a shared computer. Our site does not install analytics tools or advertising trackers. If your browser offers speech recognition and you use it to dictate in Chat, the voice is processed by your browser and its vendor, not by our server; we do not receive your voice recordings, and processing by your browser's vendor is subject to that vendor's policy.

Chat and search usage logs

For chat and search requests that we process, from the app or from web Chat, we record one usage log row: the time, your UID, the request type, the model, the status, the error code if any, the names of request fields that were not forwarded (without their values), the cost in Credit, the input and output token counts, the duration, and an internal technical marker about how the request was processed. We do not record the content of your conversations, the content of your files, or your search keywords in this log. This log is limited to the last 2,000 rows per day (the day is in UTC). Beyond that limit, this log is not deleted automatically; you can ask for it to be deleted through vibetokenapi1@gmail.com.

Remote control

The remote-control feature is off until you turn it on yourself in the app. When it is on, traffic between your browser and your computer passes through our relay server end-to-end encrypted, so we cannot read it. All we can see is technical data: the UID, the device role, the device id, the message size, and the time. The relay does not store the content it forwards, and remote conversation history is not stored on our server. The browser you use to control the app stores the pairing identity (a key that cannot be exported and the data of the paired computer) in that browser's IndexedDB.

Server technical logs

HTTP requests to our server are recorded in the system log as the method, the path (without query parameters), the status, and the processing time. Our service application does not store users' IP addresses in its database. Our server and hosting providers may record IP addresses in technical logs for security and troubleshooting, and keep them only as long as needed for that purpose. For certain failures, for example a malformed request, the error log may contain a small fragment of that request.

API usage data

This section applies if you create and use VibeCode API keys.

API keys

An API key is shown once, when you create it. Our server does not store the key itself; it stores the SHA-256 fingerprint (hash) of the key, the name you gave it, its last four characters, the date it was created, and the time it was last used, so we cannot show your key to you again. When a key is revoked, its hash is removed from the account record, while the name, the last four characters, and the dates it was created and revoked are kept for 31 days so you can recognize keys you have revoked, and then deleted.

Per-request records

For each API request that passes the key check and the rate limit, we record one row: the time, the request id, the key id, the model, the HTTP status, the result or error code, the input and output token counts, the cost in Credit, a flag showing whether the token figures come from the model provider's count or are estimated, the processing time, and whether the response was streamed. The content of messages, files, images, and model answers is not recorded. These rows are kept for 30 days and you can see them on the Credit page; requests rejected for exceeding the rate limit are not recorded. Deletion is run periodically, so a technical failure can delay the deletion of rows that are past their retention period.

Daily summaries

From these records we build daily summaries (the day is in WIB, which is UTC+7) per key and per model: the number of requests, input tokens, output tokens, cost, number of failed requests, and number of requests whose figures were estimated. These summaries are used for your usage charts and are kept without a time limit. We also keep a combined daily summary of all users, without user identities, for the administrator dashboard.

Administrator records

Administrators also have an API traffic record containing the UID, model, status, code, token counts, cost, and duration, without message content. This record keeps only the last 2,000 requests per day (the day is in UTC, not WIB) and is deleted after 30 days. Because of that limit, the administrator record is not a complete archive; your own 30-day archive is the request log on the Credit page.

API account list

To run the service and prevent abuse, administrators keep a list of accounts that have created API keys: the UID, the email from the sign-in token when the key was created, the number of active keys, the date the first key was created, and the block status. Administrators can revoke a key or block an account's API access.

Rate limit

To enforce the per-minute rate limit on each account, we store the timestamps of your account's most recent requests in the API account record.

API request content

The content of API requests (messages, files, and images) and the model's answers are not stored in our database. That content is processed in server memory, forwarded to the model provider as described in the section Model providers and other third parties, and the answer is returned to you. If you fill in the user field of a request, its value is forwarded to the model provider as well, so do not put personal data in it.

What we use data for

We use your data to run the service you ask for, that is, for the following purposes:

  • running the service: recognizing your account, forwarding requests to model providers, storing web Chat history, and showing your balance and usage;
  • billing and bookkeeping: calculating cost in Credit, matching QRIS payments to your transactions, and activating plans;
  • security and abuse prevention: enforcing rate limits, blocking keys or accounts, and monitoring unusual usage, including use of the internal routes of the app and web Chat outside the VibeCode app and web Chat;
  • supporting you and managing the service: finding accounts, correcting balances or plans, and responding to your requests;
  • understanding usage through aggregate figures, such as which models are used most, to plan capacity and cost.

We do not sell your personal data and do not use it for advertising. We ourselves do not use the content of your messages or files to train models. We disclose your data to the authorities only when the law requires it.

Model providers and other third parties

Models from VibeCode

If you use models from VibeCode, whether in the app, web Chat, or the API, we forward the content of your request to third-party AI model providers for processing. This happens because you use a model feature: without forwarding the content of your message, your request cannot be answered. What is forwarded is your messages, the files and images you include, and the tool results sent by the agent. The provider receives it from our server using our credentials, and we do not add your UID or email to that request. The provider processes that content outside Indonesia, under its own policies, including how long it keeps it, which we do not control. We ourselves do not use that content to train models.

Web search through VibeCode

When the agent searches the web through our server, the search keywords are sent to our server and then forwarded to one or more third-party web search providers. We record only that a search took place (UID, status, and duration), not the keywords. Those search providers process the keywords outside Indonesia, under their own policies.

Your own keys and custom or local endpoints

If you use your own key or a custom endpoint in the desktop app, model requests are sent directly from your device to the address you set, without passing through our server, and are subject to the policy of whoever operates that address. A local endpoint processes data on your own device.

Agent tools that reach the internet

Agent tools that reach the internet, such as fetching web pages, searching for images, and web searches that do not go through our server, run from your device. They send addresses or keywords composed by the agent directly to the relevant third-party service.

Other third-party services are contacted directly by your browser or app and can see your IP address and other technical data; each is subject to its own privacy policy:

  • Firebase and Google, for signing in and storing the account profile;
  • a third-party app-release hosting service, contacted by the desktop app to check for updates and by the website to show download links;
  • a third-party currency-exchange-rate service, contacted by your browser when you open a pricing page;
  • a third-party public model catalogue, contacted by the desktop app to fetch the list of models;
  • third-party skill indexes and sources, which the desktop app contacts when you search for or install skills in the Capabilities menu; your search terms may be sent to those services;
  • the hosting provider that serves our website and the virtual server (VPS) provider where our service runs; both are outside Indonesia.
Warning: What you send to a model may contain any personal or confidential data you include, including the content of files the agent reads. Do not send data you do not want a third-party model provider to process.

Payments

Credit top-ups and plan purchases are paid by QRIS. Our server creates a QR code with a unique amount for your transaction, and your payment is processed by the bank or e-wallet app of your choice and the QRIS network.

To know that you have paid, we read the payment confirmation from the third-party payment portal we use as the merchant. Our system reads and stores only the mutation id and the amount from the portal answer, and records the time our system received it, then matches them to your transaction. Our system does not read or store your card number, bank account number, or e-wallet name, and we do not store the payer's identity.

Warning: The payment-page link opened from the app contains a random key: anyone who holds that link can see the status, the amount, and the QR code of that payment without signing in. Do not share that link.

How long data is kept

The table below summarizes how long data is kept. If a row says the system does not delete the data automatically, that data stays until it is deleted on request or by an administrator, except for any exception written in that row. Deletion of time-limited data is run periodically by the system; a technical failure can delay it.

DataStored inRetention
Sign-in account (UID, email, password managed by Firebase)FirebaseUntil the account is deleted
Account profile in Firestore (desktop app and VS Code extension)FirebaseUntil you use Delete account in the desktop app
User list (UID, email, time first seen)Our serverNot deleted automatically, except that the oldest entries can be dropped once the list is full; deleted on request
Balance, tier, plan expiry, and usage countersOur serverNot deleted automatically; stays after the account is unused or deleted until deletion is requested, except what must be kept for bookkeeping
Payment transaction records and unmatched mutationsOur serverAs long as needed for bookkeeping and legal obligations (unmatched mutations are deleted once they are finally matched or assigned by an administrator)
Payment event log (for administrators)Our serverOnly the most recent events; new events replace the oldest
Web Chat historyOur serverUntil you delete it
Conversation history, agent memory, attachments, and settings in the appYour deviceUntil you delete them
Chat and search usage logOur serverLast 2,000 rows per day (UTC); beyond that not deleted automatically, and deleted on request
Active API keys (hash, name, last four characters)Our serverUntil the key is revoked
Name and dates of revoked API keys (no hash)Our server31 days after revocation
Per-request API recordsOur server30 days
API administrator recordsOur server30 days; at most the last 2,000 requests per day (UTC)
API account list (UID, email, number of active keys, date the first key was created, block status)Our serverNot deleted automatically; an entry is dropped automatically only when the list is full and the account has no active key, no log, and is not blocked; deleted on request
Daily API usage summariesOur serverNo time limit
Sign-in session in your browserYour browserUp to 30 days (Stay signed in) or until you press Sign out
Server and proxy system logsOur server and hosting providersOnly as long as needed for security and troubleshooting

Security

  • Communication between your app, website, or API client and our server runs over HTTPS.
  • Your password is managed by Firebase and never reaches our server.
  • API keys are stored only as a hash and are shown only once.
  • The sign-in token and the model keys on your device are stored encrypted using the operating system's secure storage.
  • The service determines your account from the verified sign-in token, not from data sent by the client, so web Chat history and account data are separated per account.
  • Administrator routes answer only verified administrator accounts.
  • We limit request rates and sizes to protect the service from abuse.

Data is stored on servers outside Indonesia. Access to user data is limited to VibeCode administrators. No system is completely secure, and we cannot guarantee absolute security. If a data breach that affects you occurs, we will notify you by email to your account or by an announcement on the website, to the extent required.

Your rights over your data

You can ask for access to the personal data we store about you together with a copy, for correction of inaccurate data, or for deletion of your data.

What you can do yourself:

  • Web Chat: delete one conversation or your entire history, and download your entire history, from the Chat page.
  • API: revoke a key at any time from the API page, and see your usage and the request log for the last 30 days on the Credit page.
  • Desktop app: open Settings, the Account tab, then choose Delete my account to delete your sign-in account and your account profile in Firebase.
Warning: Deleting your account in the desktop app does not automatically delete the records on our server, namely your balance, tier and plan expiry, transactions, web Chat history, and usage logs. After the account is deleted you also can no longer access any remaining Credit balance or plan; see the Refund Policy. Delete your web Chat history from the Chat page before deleting your account if you want that history gone, and contact us through the address below to ask for the other records on our server to be deleted.

To request access, a copy, correction, or deletion of the data on our server, send a request to vibetokenapi1@gmail.com from your account email, so that we can confirm the request comes from you. We try to respond within 14 days. Requests are handled manually, and the website does not yet have a delete-account button.

After a deletion request, we still keep payment transaction records (amount, time, and your UID) because they are needed for bookkeeping.

Children

The service is for users aged 18 years or older. We do not knowingly collect data from users below that age, and we delete it if we learn of it.

Changes to this policy

We may update this policy. Changes are announced through a banner on the website and in the app, and through the date of the latest update at the top of this page, and take effect from that date.

The Indonesian version of this document is the authoritative one. If the Indonesian and English versions differ, the Indonesian version prevails.

Contact

Questions, requests, or complaints about this policy can be sent to vibetokenapi1@gmail.com. The service is operated by VibeCode, Jakarta.