VibeKit Legal
Back to the admin
Legal

VibeKit — Privacy Policy

Last updated: 25 September 2026

This Privacy Policy explains how Aeropage Limited ("Aeropage", "we", "us") collects and uses personal information in connection with VibeKit (the "Service"). It forms part of, and is incorporated into, our Terms of Service.

Capitalised terms not defined here have the meaning given in the Terms.

1. Two different roles, and why it matters

The Service is a tool that developers ("Customers") use to build their own applications ("Customer Applications"). Personal information reaches us in two distinct ways, and our role differs in each:

2. Information we collect

2.1 Customer account data

2.2 End-user data (processed for our Customers)

If a Customer enables VibeKit's optional sign-in, sign-up, or form features, we process, on their behalf:

2.3 What we receive from Google

When you or a Customer's end user signs in with Google, we request only the openid and email scopes. Google therefore discloses to us the person's email address and whether it has been verified — nothing else. We do not receive or request their contacts, calendar, files, or any other Google data.

That email address is used to sign the person in and, for a Customer Application, to determine whether they appear in that Customer's user list. We do not use Google user data for advertising, we do not sell it, and we do not use it to train machine-learning models. Data obtained through Google APIs is used and transferred in accordance with the Google API Services User Data Policy, including its Limited Use requirements.

Where a Customer supplies their own Google OAuth client instead of using ours, their Google project's own terms apply to that relationship in addition to this Policy.

2.4 Cookies, storage, and third-party content

We do not use advertising cookies, cross-site tracking, or analytics pixels. The administrative application stores in your browser's local storage your sign-in session, the campaign tag described in Section 2.1, and interface preferences. Its fonts are served from our own servers, not from Google Fonts. (Theme fonts that a Customer chooses for its own application may be loaded from Google Fonts by that application; that is the Customer's choice.) We measure usage of the Service on our own infrastructure (see Section 5), not through third-party trackers.

2.5 Children

The Service is for business and professional use and is not directed to children. We do not knowingly collect personal information from children under 13 as a controller. Customers who operate applications used by children are responsible for complying with children's-privacy laws, as set out in Section 10.3 of the Terms.

3. How we use information

We use personal information to:

We do not sell personal information, and we do not share it for cross-context behavioural advertising.

4. Product-update and onboarding emails

When you create an account, we add your email address to our product-update list, hosted by Resend, and may send you onboarding emails triggered by your progress (for example, when you connect a data source or deploy an application). You can say no when you sign up with an emailed link (by ticking "opt out"), and you can switch product-update emails off or on at any time under My account in the admin application, by emailing privacy@aeropage.io, or by using an unsubscribe link where one is included. If you opt out, we keep your address on the list marked as unsubscribed, so that you are not added again, and we send you no onboarding emails. Opting out does not stop transactional messages about your account. We never add Customers' end users to our own lists; any mailing list a Customer configures for its forms is processed on that Customer's behalf.

5. Usage measurement

For each request to the Service we record, on Cloudflare's analytics infrastructure, the application and account it relates to, the kind of request, and its source. We use this to measure usage, enforce allowances, and plan capacity. It does not include the content of your data.

6. AI features

Some features use AI models:

We do not use your Customer Data or end-user data to train AI models. AI Agents that you connect to the Service (for example, over MCP) are chosen and controlled by you; data they retrieve is disclosed to them and their providers under your arrangements with those providers, as described in Section 12.2 of the Terms.

For Customer account data we rely on: performance of a contract (providing the Service you signed up for); legitimate interests (securing the Service, preventing abuse, measuring usage and campaign performance, improving reliability, and telling existing users about VibeKit — which you can object to at any time); and legal obligation where applicable. Where we act as a processor for end-user data, the Customer is responsible for establishing the legal basis for that processing.

8. Service providers and international transfers

We use the following providers to run the Service. They process personal information only to provide their services to us, under contractual confidentiality and security obligations:

Provider Purpose
Cloudflare Hosting, edge compute, caching, databases, file storage, session infrastructure, usage analytics, sending of sign-in and alert emails (Email Sending), AI models (Workers AI), AI request routing (AI Gateway), and website screenshots (Browser Rendering)
Supabase Customer account sign-in and project records
Google Google sign-in (only where used); Gemini model for describing design-reference websites
Resend Our product-update list and onboarding emails; backup delivery of transactional email
Airtable The Customer's own data source, connected under credentials the Customer supplies and controls

Customers may also connect their own email provider (such as Resend, Postmark, SendGrid, or Cloudflare) to send sign-in emails for their application and, with Resend, to add form submitters to their own mailing lists, and their own hosting provider for deployments. Those providers act under the Customer's own account and terms.

Aeropage Limited is established in the United States, and these providers may process data in the United States and other countries. Where personal information is transferred out of the UK or EEA, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses and the UK Addendum where applicable.

9. Security

We apply technical and organisational measures appropriate to the risk, including: encryption in transit (TLS); encryption at rest for stored credentials and stored end-user records; encrypted request and response payloads between an application and our servers; cryptographically signed session tokens; opaque identifiers so that a Customer's underlying data-source identifiers are not exposed to a browser; per-application separation of configuration and credentials; rate limiting; and restricted administrative access.

No system is perfectly secure, and the Service may contain defects. As set out in Sections 9, 10.4, and 17 of the Terms, Customers control how their applications are configured and remain responsible for assessing whether the Service's features are suitable for their data. Some content is intentionally reachable without signing in — for example, public forms, media and file links, and design-reference screenshots — and anyone holding such a link may be able to open it. If a personal-data breach affects you, we will notify you and, where required, the relevant authorities, without undue delay.

10. Retention

Data How long we keep it
Account, projects, configuration, and stored credentials While your account is active, until you delete them (see below)
Request and alert logs 30 days
Sign-in events 90 days
Configuration change log (including AI Agent changes) 1 year
End-user sign-in identities and matched records While the Customer's application uses them, until the Customer asks us to delete them; access that has been revoked is deleted after 90 days without re-validation, and a sign-in identity is deleted once it has no remaining application access
End-user sessions Until they expire (Customer-configured; 7 days by default, up to 1 year) or are revoked
Sign-in links and codes 15 minutes
Files uploaded through forms 7 days, then deleted automatically
Cached copies of Customer data at the edge Replaced when data changes; unused copies may persist in cache for up to 30 days before they are discarded
Design-reference library entries and screenshots Indefinitely, as part of the shared library
Campaign tag in your browser 30 days
Development-helper device records 90 days after the device was last seen
AI Agent authorizations Unused authorization codes: 1 day after they expire; revoked authorizations: 30 days after revocation
Terms acceptance records Kept after your account is deleted, as a legal record of what you agreed to (no email address is stored with them)

Deletion. You can delete data yourself in the admin application:

Deletion doesn't touch your Airtable bases or any account you hold with another provider. Usage measurements (Section 5) and copies of data that remain briefly in edge caches can't be individually erased; they're discarded when they expire. We keep limited records where required for legal, accounting, or security reasons, such as terms acceptance records. You can also ask us to delete your data by emailing privacy@aeropage.io from your account email address, and we'll complete it within 30 days. A Customer may ask us to delete end-user records processed on its behalf at any time, and we'll action that without undue delay.

11. Your rights

Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information; to object to or restrict certain processing, including direct marketing; to withdraw consent where processing is based on consent; and to complain to your data-protection authority (in the UK, the Information Commissioner's Office). Residents of California and other US states with comprehensive privacy laws have comparable rights, including the right not to be discriminated against for exercising them — noting that we do not sell personal information or share it for cross-context behavioural advertising.

To exercise any of these rights over data we hold as a controller, contact privacy@aeropage.io. We will respond within the period required by applicable law. If your request concerns data held within an application built by one of our Customers, please contact that Customer directly — they control it, and we will support them in responding.

12. Changes to this Policy

We may update this Policy from time to time. If we make a material change, we will update the "Last updated" date above and, where appropriate, notify you through the Service or by email. We will update the provider list in Section 8 before adding a new provider that processes end-user data.

13. Contact

Aeropage Limited
1111B S Governors Ave STE 7987, Dover, DE 19904, United States
Privacy: privacy@aeropage.io
Legal: legal@aeropage.io