summer_campaignsummer_campaign
Kick off 2026 with a better workspace: Up to $600 off per Vibe BoardStart 2026 with Vibe: Save $600 now
hero-bg-righthero-bg-lefthero-bg-left

Vibe Privacy Policy

This Privacy Policy explains how Vibe Inc. (“Vibe,” “we,” “us,” or “our”) collects, uses, discloses, and protects Personal Data when you interact with our websites, products, devices, and services.

Important: This policy covers both business (B2B) and consumer (B2C) use. For business customers, the organization (e.g., your employer) may act as the administrator of your workspace and control settings that affect data collection and retention.

Last Updated: January 21, 2026

1. Scope: What This Policy Covers

This Privacy Policy applies to:

  1. Marketing Website and Online Store ("Site") — including browsing, marketing pages, and purchases.
  2. SaaS Applications ("Services") — including Vibe Canvas, Vibe Admin Console, our web/mobile apps, and related cloud features.
  3. Vibe Devices — including Vibe Bot and other Vibe-branded devices and firmware ("Devices").
  4. AI Features ("Vibe AI") — including transcription, summaries, conversational assistance, and other AI-enabled features.
  5. Integrations — such as Microsoft Teams, Zoom, Google Meet, Slack, Google Drive, and Microsoft 365.
This policy does not cover third-party products or services (including third-party apps installed on a Device) that have their own privacy policies.

2. Definitions

  • "Personal Data" means information that identifies, relates to, describes, or could reasonably be linked to an individual.
  • "Customer Content" means content submitted to or created within the Services and Devices (e.g., whiteboards, files, images, recordings, transcripts, and AI outputs).
  • "Workspace" means an account or organizational environment created in our Services.
  • "Subprocessor" means a third-party service provider that processes Personal Data on our behalf.

3. Personal Data We Collect

3.1 Site Data (Marketing Website and Store)

When you visit our Site, we may collect:

  • Device/Browser Data: IP address, browser type, OS, time zone, language, device identifiers for the browser session.
  • Usage Data: pages viewed, referrer URL, clicks, and interaction patterns.
  • Cookies and Similar Technologies: cookies, pixels, SDKs, and similar tools used for analytics and marketing (see Section 8).

If you make a purchase through our store, we collect:

  • Order and Account Data: name, email, phone number, billing/shipping address, order history.
  • Payment Data: payment information is processed by our payment processors. We do not intentionally store full payment card numbers except as provided by the processor for transaction handling and compliance.

3.2 Account and Workspace Data (SaaS)

When you create or use a Vibe account or join a Workspace, we may collect:

  • Identity and Profile Data: name, email address, display name, profile image (if provided).
  • Workspace Data: organization name, membership, roles/permissions, and administrative settings.
  • Authentication Data: login events, timestamps, IP address, and security-related signals.

3.3 Customer Content (SaaS and Devices)

Depending on features you use, Customer Content may include:

  • Whiteboards, documents, files, images, and comments.
  • Audio/Video Recordings and Transcripts when you use recording or transcription features.
  • AI Inputs and Outputs (e.g., prompts, transcripts provided for summarization, and generated summaries or responses).

3.4 Audio/Video for Conferencing

When you use Devices or Services for conferencing:

  • Real-Time Streams: audio/video may be processed and transmitted to the conferencing platform you select. Unless you enable recording or another storage feature, real-time streams are processed for transmission and not stored by Vibe as recordings.
  • Meeting Metadata: we may process basic metadata such as device used, meeting duration, feature toggles, and connection diagnostics.

3.5 Device Data and Diagnostics

Devices may collect and transmit:

  • Device Identifiers: serial number, MAC address, and device ID.
  • Device Telemetry: firmware/app version, uptime, performance metrics, and connectivity status.
  • Crash Logs and Diagnostics: logs necessary to troubleshoot and improve reliability and security.

3.6 On-Device Sensor Processing

Devices may perform real-time local processing for features such as auto-framing, speaker tracking, and interaction readiness.

  • This processing occurs on-device.
  • We do not upload or store raw sensor data for these local features, and it is discarded after the real-time interaction completes.

3.7 Data We Receive from Integrations and Other Sources

We may receive limited information when you connect integrations, such as:

  • Microsoft Teams: primary email address and display name associated with your Microsoft account.
  • Zoom: OAuth tokens stored on-device to enable the integration and communicate with Zoom.
  • Other Integrations (e.g., Google Meet, Slack, Google Drive, Microsoft 365): identity and authorization information and content only as needed to provide the integration features you enable.

We do not receive your password for third-party services.

4. How We Use Personal Data

We use Personal Data to:

  1. Provide and Operate the Services and Devices
    • Create and manage accounts and Workspaces.
    • Deliver core product functionality, sync across Devices and apps, and provide integrations.
  2. Process Orders and Provide Customer Support
    • Fulfill purchases, deliver products, send confirmations, and provide support.
  3. Maintain Security, Prevent Fraud, and Ensure Reliability
    • Authenticate users, detect misuse, secure systems, and troubleshoot incidents.
    • Analyze crash logs and diagnostics.
  4. Improve Products and User Experience
    • Understand usage patterns and improve performance and usability.
  5. Marketing and Communications (Where Permitted)
    • Send product updates, newsletters, and marketing communications.
    • Conduct targeted advertising and measurement on the Site (see Section 8).

5. AI Processing and Data Use

5.1 AI Service Provision

When you use Vibe AI features (e.g., transcription, summaries, conversational assistance), relevant Customer Content (such as audio recordings or text) may be transmitted to trusted third-party AI providers to generate the requested output.

5.2 No Model Training / No Retention by AI Provider

Vibe does not use your Customer Content to train or fine-tune third-party AI foundation models. Our AI provider is contractually required to process data only to produce the requested output and under no-training/no-retention terms.

5.3 Control Over AI Features

AI features are only used when you or your Workspace administrator enable or invoke them. Workspaces may have controls to enable or disable AI features, depending on your plan and configuration.

6. How We Share Personal Data

We share Personal Data only as described below:

6.1 Subprocessors (Service Providers)

We use Subprocessors to operate and improve our services, including:

  • Hosting/Infrastructure: Amazon Web Services (AWS) (primary region us-west-2, backups in us-east-1)
  • AI Processing: OpenAI
  • Analytics and Event Processing: Google Analytics, Mixpanel, RudderStack, Redshift (data warehouse)
  • Communications: Klaviyo (marketing emails), HubSpot (CRM), Google Workspace (email)
  • Reliability and Logging: Sentry (error reporting), Grafana (log collection)

Subprocessors are contractually required to protect Personal Data and use it only to provide services to Vibe.

6.2 Integrations You Enable

When you connect integrations (e.g., Teams, Zoom, Meet, Slack, Drive, Microsoft 365), certain data may be transmitted to and from those third parties to provide the integration. Those third parties process your data under their own privacy policies.

We may disclose Personal Data if we believe in good faith it is necessary to:

  • comply with applicable law or legal process;
  • respond to lawful requests from public authorities;
  • protect the rights, security, and safety of Vibe, our users, or others.

7. Data Retention and Deletion

We retain Personal Data only as long as necessary for the purposes described in this policy.

  • Customer Content: stored until you (or your Workspace administrator) delete it.
  • Deleted Customer Content:retained for up to 7 days after deletion to support operational recovery and integrity, then permanently deleted.
  • Logs and Diagnostics: retained for up to 90 days.
  • Order/Billing Records: retained as required for accounting, tax, and legal obligations.

Backups may store data for a limited period consistent with the retention windows above.

8. Cookies, Tracking, and Advertising

8.1 Cookies and Similar Technologies

We use cookies and similar technologies on our Site and (in some cases) within our Services to:

  • provide core functionality;
  • understand usage and performance;
  • measure marketing effectiveness;
  • deliver interest-based advertising where permitted.

8.2 Analytics and Marketing Partners

We use partners such as Google Analytics, Mixpanel, RudderStack, Klaviyo, and RB2B/Retention.com on our marketing Site.

8.3 Your Choices

You can control cookies through your browser settings and, where available, our cookie banner and preference tools.

RB2B/Retention.com Opt-Out: You may opt out by using the vendor opt-out mechanism: https://app.retention.com/optout

We may not respond to "Do Not Track" signals where not required by law.

9. International Data Transfers

Vibe is based in the United States. Personal Data may be processed and stored in the U.S., including in AWS regions us-west-2 (primary) and us-east-1 (backup). We may transfer data across borders as required to operate our services.

10. Security

We implement industry-standard administrative, technical, and organizational measures to protect Personal Data, including:

  • encryption in transit (TLS 1.2+) and encryption at rest (AES-256 or equivalent);
  • access controls and least-privilege practices;
  • logging and monitoring;
  • security testing and incident response procedures.

SOC 2: Vibe maintains a SOC 2 program and can provide relevant documentation under NDA.

11. HIPAA and Regulated Use

Vibe supports regulated use cases and will sign a Business Associate Agreement (BAA) upon request for eligible customers.

When a BAA is in place, we will process Protected Health Information (PHI) in accordance with the BAA and applicable HIPAA requirements for the covered services.

12. Children’s Privacy

The Site is not intended for children under 13. If you believe a child has provided Personal Data to Vibe, please contact us and we will take appropriate steps.

13. Updates to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. We will post the updated version with a new effective date.

14. Contact Us

If you have questions or requests regarding privacy, contact:

Email: privacy@vibe.us

Mail: Vibe Inc. 2018 156th Ave NE, Office 165 Bellevue, WA 98007 United States