VIBEVIDEO

Privacy Policy

Last updated: [EFFECTIVE DATE] · DRAFT — pending legal review

⚠ Template draft. [PLACEHOLDERS] and final wording must be completed by counsel before launch.

1. Who we are & scope

This Privacy Policy explains how [COMPANY LEGAL NAME] ("VibeVideo", "we") collects, uses, and shares information when you use the service. It applies to our app and website. By using VibeVideo, you agree to this policy and our Terms of Service.

2. Information we collect

  • Account information — your email address and (if set) your public username.
  • Content you provide — the prompts and settings you enter, and the photos and other media you upload to generate content.
  • Content you create — the images and videos generated for you, and whether you mark them public.
  • Payment information — handled by our payment processor; we receive limited billing details, not full card numbers.
  • Usage & device data — log data, device/browser type, and basic analytics so the service works and stays secure.

3. Biometric & facial data (and our retention + destruction policy)

Photos you upload may contain a face, and processing a face to generate your content may involve facial geometry, which can be considered biometric data. We process this data only to create the content you request, based on your consent (collected when you sign up and when you upload). We do not sell, lease, trade, or otherwise profit from your biometric data, and we do not use it to identify you or to train AI models without your separate, explicit consent.

Retention & destruction: uploaded photos that are not used to create content are deleted within [7 days]. A photo used to create a saved creation is retained only while that creation exists, so the creation can be displayed and re-created. We permanently delete your uploaded photos and any associated biometric data when you delete the related creation or your account, when the purpose for collection has been satisfied, or within [3 years] of your last interaction — whichever comes first. This section serves as our publicly available written retention and destruction policy for biometric data.

4. How we use information

To provide and operate the service; to generate the content you request; to maintain your library and the public feed; to process payments; to keep the service secure and prevent abuse; to provide support; to comply with law; and to improve the service (using aggregated or de-identified data — not your biometric data — unless you give separate consent).

5. How we share information

We do not sell your personal information or biometric data. We share:
  • AI generation providers — your prompts and uploads are transmitted to the provider that fulfils your request (including RelayGPU/OpenGPU and underlying model providers), solely to produce your output.
  • Service providers — hosting, storage, and payment processors that operate the service under contract.
  • The public feed — only content you choose to make public is shown to and remixable by other users.
  • Legal & safety — where required by law, to protect rights and safety, or to investigate violations.
  • Business transfers — in connection with a merger, acquisition, or sale of assets, subject to this policy.

6. The public feed & sharing

Your creations are private by default. If you make one public, it (and, if you include it, its source image and prompt) becomes visible to other users and may be remixed. You can make content private or delete it at any time; copies or remixes others already made may persist. See our Terms for the sharing license.

7. Data retention

We keep account data while your account is active. Generated content is kept until you delete it or close your account. Uploaded source photos follow the biometric retention schedule in Section 3. We may retain limited data where required for legal, security, or accounting reasons.

8. Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, port, or restrict the use of your personal data, to object to certain processing, and to withdraw consent. This includes rights under the GDPR (EU/UK), the CCPA/CPRA and other US state laws, and biometric-privacy laws such as the Illinois BIPA. You can exercise these rights — including deleting your account and content — in the app or by contacting us at [CONTACT EMAIL]. We will not discriminate against you for exercising your rights.

9. Children's privacy

VibeVideo is not intended for anyone under [18], and we do not knowingly collect personal or biometric data from children. If you believe a minor has provided us data, contact us and we will delete it.

10. International data transfers

We and our providers may process and store your data in countries other than where you live, including the United States. Where required, we use appropriate safeguards (such as standard contractual clauses) for these transfers.

11. Cookies & tracking

We use cookies and similar technologies that are necessary for the service to function (e.g., to keep you signed in) and, where applicable, for analytics. Where required by law, we ask for your consent to non-essential cookies and let you accept or reject them. [Detail the specific cookies/analytics in use.]

12. Security

We take reasonable measures to protect your data: passwords are hashed, sessions are stored as hashed tokens, and sensitive credentials are encrypted at rest. No system is perfectly secure, but we work to protect your information and to limit access to it.

13. Changes to this policy

We may update this policy from time to time. If we make material changes — especially to how we handle biometric data — we will provide notice and, where required, ask for renewed consent.

14. Contact & data requests

Questions or requests about your data? Contact us at [CONTACT EMAIL] or [COMPANY ADDRESS]. [If you have an EU/UK representative or Data Protection Officer, list them here.]