VibeDirector
Privacy Policy
Last updated: September 6, 2026
Who we are
VibeDirector is responsible for the personal information described in this policy. Contact us at support@vibedirector.io with questions or requests about your information.
The public website introduces VibeDirector. A separate password-protected private app supports authorized testers, account sign-in, prepared-video uploads, and TikTok sandbox connections. General access and public posting await platform review. This policy covers both the website and the private app.
Information on this website
- Our hosting provider, Vercel, may process your IP address, browser information, requested URLs, timestamps, and error or security information to deliver and protect the site.
- If you email us, we receive your email address, message, and any information you choose to include. Please do not send passwords or access tokens.
- The site may store a display-theme preference in your browser. If you enter the private-access password successfully, a necessary session cookie remembers that access for up to eight hours. Security checks process your IP address to limit password attempts. We do not add advertising trackers or analytics cookies to this website.
Connected accounts and content
Information needed for available account and publishing features includes your account email, workspace details, uploaded media, connected-account information, and publishing choices. Creative features, where available, also process the prompts and content you provide.
If you choose to connect TikTok, TikTok’s authorization screen will explain the permissions requested. The integration uses account identifiers, profile information available under those permissions, access and refresh tokens, and publishing information such as captions, privacy settings, and post status. We do not receive your TikTok password. A connection is used to provide the features you authorize; publishing requires your explicit action.
If you connect an Instagram Business or Creator account, Instagram’s authorization screen explains the requested account and content-publishing permissions. We process the authorized account’s identifiers and username, encrypted access tokens, and publishing data such as the selected video, caption, media identifiers, and publication status. We do not receive your Instagram password. The connection is used to identify your selected professional account and publish content when you explicitly request it.
Why information is used
We use website and security information to operate and protect the site, and correspondence to answer your requests. Where European data protection law applies, our basis is our legitimate interest in providing a secure website and responding to enquiries, or taking steps you request before providing a service. Account and content processing necessary for a service is based on performing that service’s agreement. We ask for consent where required for optional processing, and you may withdraw it.
Sharing and service providers
Vercel hosts the website, Render runs the private application APIs, and Supabase provides account authentication, database hosting, and private video storage. See Vercel’s Privacy Notice. Email providers process support correspondence. We do not sell personal information or share it for targeted advertising.
When product features are enabled, information needed for your chosen action will be sent to the relevant storage, processing, or AI provider, or connected platform such as Instagram (Meta) or TikTok. Publishing makes your content visible according to the settings you choose there. Those platforms also process information under their own policies. We may disclose information when legally required or necessary to protect rights and security.
Providers may process information outside your country. Where applicable law requires safeguards for international transfers, those safeguards must be in place before a transfer occurs. Contact us for information about providers and safeguards relevant to your use.
Retention and security
We keep support correspondence for as long as needed to respond and resolve the enquiry, and to meet applicable legal obligations. Technical logs follow the hosting provider’s configured retention. Retention depends on the purpose, security needs, and legal requirements.
For connected-account features, tokens are retained only while needed for an active connection and removed or invalidated when disconnected. Workspace content is retained while needed to provide the service or until deleted, subject to necessary backup, security, and legal retention. Access controls and encryption protect stored connection tokens. No transmission or storage system can be guaranteed completely secure.
Your choices and rights
Email support@vibedirector.io to request access, correction, or deletion of information. Depending on applicable law, you may also have rights to portability, restriction, objection, withdrawal of consent, and a complaint to your local data protection authority. We may need to verify your identity before acting on a request.
You can disconnect an available account connection in the app or revoke VibeDirector’s access through the platform’s settings. Disconnecting stops future authorized access; it does not automatically remove content already published to Instagram or TikTok. Manage published posts on the relevant platform. Follow our data deletion instructions to request deletion of information held by VibeDirector, including connected-account data.
Children and policy updates
VibeDirector is not directed at children under 13. If you believe a child has provided personal information to us, contact us so we can investigate and remove it as appropriate. Connected platforms may have additional age requirements.
We will publish changes here with an updated date and provide additional notice when required.
