VibeKit — Privacy Policy
Last updated: 25 September 2026
This Privacy Policy explains how Aeropage Limited ("Aeropage", "we", "us") collects and uses personal information in connection with VibeKit (the "Service"). It forms part of, and is incorporated into, our Terms of Service.
Capitalised terms not defined here have the meaning given in the Terms.
1. Two different roles, and why it matters
The Service is a tool that developers ("Customers") use to build their own applications ("Customer Applications"). Personal information reaches us in two distinct ways, and our role differs in each:
- Customer account data — we are the controller. Information about the developer who signs up for VibeKit: their account, their projects, and their configuration. We decide how this is used, and this Policy governs it.
- End-user data — we are a processor. Information about the people who use a Customer Application — who sign in to it, sign up through it, or submit one of its forms. We process it on the Customer's instructions, to deliver the features the Customer switched on, under the data processing terms in Section 11 of the Terms. The Customer decides what is collected and why, is the controller of that data, and is responsible for giving their own users a privacy notice and obtaining any consents required. If you use an application built with VibeKit and want to exercise your rights, contact the operator of that application; we will assist them in responding.
2. Information we collect
2.1 Customer account data
- Account details — your email address, and the fact that you signed in with Google, an emailed sign-in link, or an emailed one-time code. We do not use passwords for production accounts. Sign-in is handled by our authentication provider (Supabase).
- Sign-up source — if you arrive through a link carrying a campaign tag (such as
?source=orutm_source), your browser remembers that tag for up to 30 days and we record it on your account when you sign up, so we know which campaign brought you. - Project and application configuration — project names, briefs, plans, chosen technology stack, themes and design settings, the data queries you register, your authentication settings, your deployment preferences, and any design-reference website addresses you submit.
- Credentials you connect — such as Airtable personal access tokens, and any Google OAuth client secret or email-provider API key you choose to supply. These are encrypted at rest (AES-256-GCM) before storage and are not shown again in the admin application once saved. One exception is deliberate: a "log in as" secret for testing your own application may be included in the setup prompt you give to your own AI coding agent.
- Usage and operational records — request logs, per-application usage counts, query statistics, alert events, a log of configuration changes (including changes made by an AI Agent you connected over MCP), and, when you use the development helper, the IP address, approximate country, browser type, and page origin of your development devices. Configuration change records are redacted so that they do not contain secret values.
- Terms acceptance — when you accept our Terms of Service and Privacy Policy, we record which version you accepted, when, your approximate country, and your browser type, so we can show that you agreed.
- Messages you send us — if you contact us, the content of your message and our reply.
2.2 End-user data (processed for our Customers)
If a Customer enables VibeKit's optional sign-in, sign-up, or form features, we process, on their behalf:
- Identifiers — the email address used to sign in, or, for access-code ("passkey") sign-in, a pseudonymous identifier linked to the person's record in the Customer's user list. One sign-in identity per email address is shared across the VibeKit applications that person uses; each Customer only sees access for its own application.
- The matched record from the Customer's Airtable user list, together with any access groups the Customer has defined. It is encrypted at rest, both in our database and in the working copy held in our session infrastructure while a session is active (so that live updates work).
- Sign-up and form submissions — the details a person enters into a Customer's sign-up form or public form, which we pass into the Customer's Airtable base, and any files they upload.
- Sign-in events — the time, method (Google, emailed link or code, access code, or the Customer's "log in as" tool), and outcome of each attempt. Customers use these to detect unauthorised access attempts.
- Session state — cryptographically signed session tokens. Customers choose how long sessions last (by default 7 days).
- Mailing-list and notification destinations — if a Customer configures a form to add submitters to a mailing list or to email a notification, the submitter's email address, name, and submitted details are sent to that destination on the Customer's behalf. Mailing lists are always in the Customer's own Resend account, using the Customer's own key; we never add form submitters to a list in our account.
2.3 What we receive from Google
When you or a Customer's end user signs in with Google, we request only the openid and email scopes. Google therefore discloses to us the person's email address and whether it has been verified — nothing else. We do not receive or request their contacts, calendar, files, or any other Google data.
That email address is used to sign the person in and, for a Customer Application, to determine whether they appear in that Customer's user list. We do not use Google user data for advertising, we do not sell it, and we do not use it to train machine-learning models. Data obtained through Google APIs is used and transferred in accordance with the Google API Services User Data Policy, including its Limited Use requirements.
Where a Customer supplies their own Google OAuth client instead of using ours, their Google project's own terms apply to that relationship in addition to this Policy.
2.4 Cookies, storage, and third-party content
We do not use advertising cookies, cross-site tracking, or analytics pixels. The administrative application stores in your browser's local storage your sign-in session, the campaign tag described in Section 2.1, and interface preferences. Its fonts are served from our own servers, not from Google Fonts. (Theme fonts that a Customer chooses for its own application may be loaded from Google Fonts by that application; that is the Customer's choice.) We measure usage of the Service on our own infrastructure (see Section 5), not through third-party trackers.
2.5 Children
The Service is for business and professional use and is not directed to children. We do not knowingly collect personal information from children under 13 as a controller. Customers who operate applications used by children are responsible for complying with children's-privacy laws, as set out in Section 10.3 of the Terms.
3. How we use information
We use personal information to:
- operate, maintain, and secure the Service, and deliver configuration and data to Customer Applications;
- authenticate Customers and, on a Customer's instructions, their end users;
- send transactional messages, such as sign-in links and codes, welcome and account messages, and alert digests a Customer has enabled;
- send you product updates and onboarding emails about VibeKit (see Section 4);
- provide AI-assisted features (see Section 6);
- understand how the Service is used, including which campaigns bring new users, and plan capacity;
- detect, investigate, and prevent abuse, fraud, and security incidents;
- comply with legal obligations, and diagnose and fix faults.
We do not sell personal information, and we do not share it for cross-context behavioural advertising.
4. Product-update and onboarding emails
When you create an account, we add your email address to our product-update list, hosted by Resend, and may send you onboarding emails triggered by your progress (for example, when you connect a data source or deploy an application). You can say no when you sign up with an emailed link (by ticking "opt out"), and you can switch product-update emails off or on at any time under My account in the admin application, by emailing privacy@aeropage.io, or by using an unsubscribe link where one is included. If you opt out, we keep your address on the list marked as unsubscribed, so that you are not added again, and we send you no onboarding emails. Opting out does not stop transactional messages about your account. We never add Customers' end users to our own lists; any mailing list a Customer configures for its forms is processed on that Customer's behalf.
5. Usage measurement
For each request to the Service we record, on Cloudflare's analytics infrastructure, the application and account it relates to, the kind of request, and its source. We use this to measure usage, enforce allowances, and plan capacity. It does not include the content of your data.
6. AI features
Some features use AI models:
- Planning and generation — briefs, plans, page designs, and stack recommendations are generated by models running on Cloudflare Workers AI, using the project information you provide.
- Describing your data — the feature that describes an Airtable view sends the view's field names and a sample of up to five records, with each value shortened, to a model on Cloudflare Workers AI. Those records may contain personal information from your base.
- Design references — when you submit a website address as a design reference, we fetch and screenshot the page using Cloudflare Browser Rendering and describe it using Google Gemini (through Cloudflare AI Gateway), with a Cloudflare Workers AI model as a fallback. The address, screenshot, and description are stored in a design library that other VibeKit users can see, and screenshots are stored at publicly accessible addresses. We do not record who submitted a reference.
We do not use your Customer Data or end-user data to train AI models. AI Agents that you connect to the Service (for example, over MCP) are chosen and controlled by you; data they retrieve is disclosed to them and their providers under your arrangements with those providers, as described in Section 12.2 of the Terms.
7. Legal bases (where the UK/EU GDPR applies)
For Customer account data we rely on: performance of a contract (providing the Service you signed up for); legitimate interests (securing the Service, preventing abuse, measuring usage and campaign performance, improving reliability, and telling existing users about VibeKit — which you can object to at any time); and legal obligation where applicable. Where we act as a processor for end-user data, the Customer is responsible for establishing the legal basis for that processing.
8. Service providers and international transfers
We use the following providers to run the Service. They process personal information only to provide their services to us, under contractual confidentiality and security obligations:
| Provider | Purpose |
|---|---|
| Cloudflare | Hosting, edge compute, caching, databases, file storage, session infrastructure, usage analytics, sending of sign-in and alert emails (Email Sending), AI models (Workers AI), AI request routing (AI Gateway), and website screenshots (Browser Rendering) |
| Supabase | Customer account sign-in and project records |
| Google sign-in (only where used); Gemini model for describing design-reference websites | |
| Resend | Our product-update list and onboarding emails; backup delivery of transactional email |
| Airtable | The Customer's own data source, connected under credentials the Customer supplies and controls |
Customers may also connect their own email provider (such as Resend, Postmark, SendGrid, or Cloudflare) to send sign-in emails for their application and, with Resend, to add form submitters to their own mailing lists, and their own hosting provider for deployments. Those providers act under the Customer's own account and terms.
Aeropage Limited is established in the United States, and these providers may process data in the United States and other countries. Where personal information is transferred out of the UK or EEA, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and the UK Addendum where applicable.
9. Security
We apply technical and organisational measures appropriate to the risk, including: encryption in transit (TLS); encryption at rest for stored credentials and stored end-user records; encrypted request and response payloads between an application and our servers; cryptographically signed session tokens; opaque identifiers so that a Customer's underlying data-source identifiers are not exposed to a browser; per-application separation of configuration and credentials; rate limiting; and restricted administrative access.
No system is perfectly secure, and the Service may contain defects. As set out in Sections 9, 10.4, and 17 of the Terms, Customers control how their applications are configured and remain responsible for assessing whether the Service's features are suitable for their data. Some content is intentionally reachable without signing in — for example, public forms, media and file links, and design-reference screenshots — and anyone holding such a link may be able to open it. If a personal-data breach affects you, we will notify you and, where required, the relevant authorities, without undue delay.
10. Retention
| Data | How long we keep it |
|---|---|
| Account, projects, configuration, and stored credentials | While your account is active, until you delete them (see below) |
| Request and alert logs | 30 days |
| Sign-in events | 90 days |
| Configuration change log (including AI Agent changes) | 1 year |
| End-user sign-in identities and matched records | While the Customer's application uses them, until the Customer asks us to delete them; access that has been revoked is deleted after 90 days without re-validation, and a sign-in identity is deleted once it has no remaining application access |
| End-user sessions | Until they expire (Customer-configured; 7 days by default, up to 1 year) or are revoked |
| Sign-in links and codes | 15 minutes |
| Files uploaded through forms | 7 days, then deleted automatically |
| Cached copies of Customer data at the edge | Replaced when data changes; unused copies may persist in cache for up to 30 days before they are discarded |
| Design-reference library entries and screenshots | Indefinitely, as part of the shared library |
| Campaign tag in your browser | 30 days |
| Development-helper device records | 90 days after the device was last seen |
| AI Agent authorizations | Unused authorization codes: 1 day after they expire; revoked authorizations: 30 days after revocation |
| Terms acceptance records | Kept after your account is deleted, as a legal record of what you agreed to (no email address is stored with them) |
Deletion. You can delete data yourself in the admin application:
- Delete a project — this permanently erases the project and its application: the live application stops working (sign-ins immediately, everywhere else within about a minute), and its configuration, end-user sign-in identities and sessions, sign-in history, logs, uploaded files, and specifications are deleted. Your saved Airtable tokens stay in your account until you delete them or your account.
- Delete your account (under My account) — this permanently erases every project and application you own, your saved tokens, your connected AI Agents and their change log, your product-update list entry, and your sign-in. Your sign-in is shared with other Aextra products, such as ReMail, so access to those is deleted too.
Deletion doesn't touch your Airtable bases or any account you hold with another provider. Usage measurements (Section 5) and copies of data that remain briefly in edge caches can't be individually erased; they're discarded when they expire. We keep limited records where required for legal, accounting, or security reasons, such as terms acceptance records. You can also ask us to delete your data by emailing privacy@aeropage.io from your account email address, and we'll complete it within 30 days. A Customer may ask us to delete end-user records processed on its behalf at any time, and we'll action that without undue delay.
11. Your rights
Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information; to object to or restrict certain processing, including direct marketing; to withdraw consent where processing is based on consent; and to complain to your data-protection authority (in the UK, the Information Commissioner's Office). Residents of California and other US states with comprehensive privacy laws have comparable rights, including the right not to be discriminated against for exercising them — noting that we do not sell personal information or share it for cross-context behavioural advertising.
To exercise any of these rights over data we hold as a controller, contact privacy@aeropage.io. We will respond within the period required by applicable law. If your request concerns data held within an application built by one of our Customers, please contact that Customer directly — they control it, and we will support them in responding.
12. Changes to this Policy
We may update this Policy from time to time. If we make a material change, we will update the "Last updated" date above and, where appropriate, notify you through the Service or by email. We will update the provider list in Section 8 before adding a new provider that processes end-user data.
13. Contact
Aeropage Limited
1111B S Governors Ave STE 7987, Dover, DE 19904, United States
Privacy: privacy@aeropage.io
Legal: legal@aeropage.io