Privacy Policy
Effective date: 2026-04-01
What We Collect
| Data | Why | Retention | |------|-----|-----------| | Account info (email, org name) | Authentication, billing | Duration of account | | API key hashes (SHA-256) | Authentication | Duration of account | | Request metadata (latency, tokens, provider, timestamp) | Billing, observability | 90 days | | Ledger entries (amount, currency, type) | Billing records | 7 years | | IP address | Security, abuse prevention | 30 days |
We do NOT store prompt content or model responses unless you explicitly enable Conversation History.
Conversation History (Optional)
If enabled, messages are stored encrypted (AES-256-GCM) with a per-workspace data key. You can delete all data at any time via the Console or the API (DELETE /api/v1/deletion).
How We Use Data
- Routing inference requests to providers
- Computing billing charges and generating receipts
- Detecting abuse and enforcing rate limits
- Generating anonymized usage aggregates for the product
Third Parties
| Vendor | Purpose | |--------|---------| | Stripe | Payment processing (USD) | | SePay | Payment processing (VND) | | AI providers (Anthropic, OpenAI, etc.) | Inference forwarding |
We do not sell your data.
Your Rights
You may: access your data, correct inaccuracies, request deletion, export data. Contact privacy@vibecc.io.
Security
- All traffic encrypted in transit (TLS 1.3)
- Data at rest encrypted (AES-256)
- API keys stored as SHA-256 hashes
- Secrets managed via Kubernetes secrets with rotation
Contact
privacy@vibecc.io