← Vibrant Media

Legal

Privacy Policy

What we collect, why we collect it, and the rights you have over your data.

Draft — this document has not been reviewed by legal counsel. Last updated August 13, 2026. Questions: hello@vibrantmedia.ai.

Section 1

What we collect

Account data (name, email, sign-in identity via Clerk), your business profile (the brief you fill in), content the AI team produces for you, which channels you have linked and the credentials for them — encrypted at rest (AES-256-GCM) and decrypted only on our servers to publish a piece you approved or to test the connection at your request; on deployments without an encryption key nothing is stored and the app says so, usage metrics, and billing records (payments are processed by Stripe — we never see full card numbers).

If you ask us to fill your brief in from your website — or press “use the colors from your site” in your Brand kit — we also process the text of its public pages for that one request. What stays afterwards is the profile you confirmed on screen — the pages themselves are not part of your workspace data. To pick your brand colors we also open up to two of that site's own style files — the ones on its own address, or the file its website builder compiled from its settings — and only the colors are taken from them, no text.

Section 2

Why we collect it

To run the service: the AI team needs your business profile to produce relevant content; connections are needed to publish; usage metering enforces your plan's caps; analytics connections (Google Search Console, GA4) are used only to report your own growth back to you.

The text of your public pages is used for one thing only: drafting the brief you then check and correct. It is not used to train anything and not shared with other customers.

We do not sell your data or use your business content to train models for other customers.

Section 3

Where it lives and who processes it

Data is stored in tenant-isolated Postgres (Neon) with row-level security, and files in Cloudflare R2. Subprocessors include Neon, Clerk, Stripe, Anthropic, OpenAI, Google, Cloudflare, Inngest, DataForSEO, Sentry and Vercel — each receives only what its function requires. Sentry receives error messages when our software fails, and is configured not to receive your account details, a recording of your screen or the values of variables from the failing code. DataForSEO receives a short phrase from your brief when your team picks a topic, so that the topic is something people actually search for; Annex III of the DPA says exactly what that phrase contains.

When you ask us to read your website, the text of those pages goes to OpenAI — the model that drafts the profile — or, on a deployment where no OpenAI key is configured, to Anthropic's model instead, and to nobody else who could use it for anything but running that request.

Section 4

How long we keep it

The pages we read from your website are not kept at all: at most five public pages, and of each we send at most 8,000 characters — its title, its meta description, up to 2,000 characters of its JSON-LD markup and then its visible prose, assembled in that order and cut at 8,000 — and only for as long as that one request runs. Nothing from them is written to your workspace — what stays is the profile you confirmed on screen.

One line about the read does stay: a usage record with the address you asked us to read, when it ran and what it cost us. It belongs to your workspace and goes when the workspace goes — “Delete workspace” under Settings → Account removes it along with everything else.

The daily cap on site reads is deliberately outside that: we keep today's date and how many reads it has used, and those two numbers survive deletion. Otherwise the cap could be cleared by the person it applies to, one new workspace at a time.

Deleting a workspace does not erase everything, and this is the whole of what stays. Your billing and plan record, and the row that ties your organization to Stripe — for as long as the law requires us to keep them. Your email address in our records, but only while a membership in another workspace still holds it; once nothing holds it, it goes too. If you also subscribed to our newsletter from the footer of this website, that address is removed by the same click.

Deletion is not instant everywhere at once: our database keeps a short recovery window, currently six hours, from which a copy could technically be restored. After that window passes, the deleted rows are gone from backups too.

Section 5

Your rights (GDPR / CCPA)

You can export all your organization's data or delete it from the workspace settings (billing records are retained where the law requires; channel credentials are never part of an export). You can also request either by email. Disconnecting a channel erases the credentials we hold for it, so we can no longer reach it.

Section 6

Cookies

We use strictly necessary cookies for sign-in and CSRF protection. Analytics cookies, if introduced, will be consent-gated.

Section 7

Contact

Privacy questions and data requests: hello@vibrantmedia.ai.