Legal

Privacy Policy

Effective Date: May 19, 2026Last Updated: July 2, 2026

1. Who We Are and How to Contact Us

VibeLaunch is a software product and brand owned and operated directly by GlintHQ LLC, a Wyoming limited liability company (referred to in this Policy as "GlintHQ LLC," "we," "us," or "our"). There is no separate legal entity named "VibeLaunch" and no "doing business as" (DBA) filing. GlintHQ LLC is the sole data controller responsible for the personal data collected, stored, and processed through your use of the website located at vibelaunch.live (the "Site") and the remote Model Context Protocol (MCP) server located at mcp.vibelaunch.live/mcp (collectively, the "Services").

Because we are an early-stage company operated by a single founder, we do not have a designated Data Protection Officer (DPO). If you have questions about how we handle your data, or if you wish to exercise your data rights, please contact us directly at hello@vibelaunch.live. We personally review and respond to all verified inquiries within thirty (30) days.

2. What We Collect and How We Get It

We only collect the minimum amount of data necessary to provide a fast, secure, and functional app-publishing service. We do not run third-party advertising cookies, marketing trackers, or advertising pixels. We do use EU-hosted PostHog product analytics and masked session replay as described below and in our Cookie Notice.

We collect and process the following categories of data:

Data CategoryWhat We CollectHow We Collect ItWhy We Need It
Account Profile InformationPrimary email address, Google profile name, and Google profile picture URL.Shared automatically when you sign in via Google OAuth.To create, secure, and uniquely identify your VibeLaunch user account.
User-Generated ContentThe raw HTML, CSS, JavaScript code, and associated files you upload.Pasted into the Site, published on your behalf via the MCP connector, or retrieved through the connector when you ask an AI assistant to update an existing app.To host, compile, serve, and help update your live applications at a public URL.
Application MetadataCustom display names, slug URLs, publishing timestamps, and public view counts.Generated automatically by our database upon app creation.To route traffic to your apps and display your account usage limits.
Technical & Usage LogsIP address, browser user-agent string, and request timestamps.Logged automatically by Cloudflare and Supabase edge servers.To monitor network performance, prevent abuse, and block DDoS attacks.
MCP Operational EventsConnector authorization milestones and tool-result signals such as event name, tool name, status, issue code, duration, file and asset counts, stack provider names, warning counts, related user or app IDs, and small sanitized metadata. We do not store prompts, generated code, returned app HTML, files, content, OAuth tokens, auth codes, access tokens, raw IP addresses, raw tool arguments, repair snippets, or large payloads in these events.Generated when you install or use the MCP connector.To monitor connector reliability, diagnose publish failures, prevent abuse, and prepare platform review evidence without reviewing your private chat content.
Product AnalyticsPage views, product usage events, browser/session metadata, and masked session replay.Collected through EU-hosted PostHog when analytics is enabled and your browser does not send a recognized Do Not Track signal.To understand product flow, diagnose usability issues, and improve the Services without recording app code or form contents.

3. Why We Process Your Data (Legal Bases)

If you are located in the European Union (EU), United Kingdom (UK), or other jurisdictions with comprehensive privacy laws, we must disclose the legal grounds we rely on to process your personal data:

  • Contractual Necessity: We process your Account Profile, User-Generated Content, and Application Metadata strictly to fulfill our contract with you under our Terms of Service (specifically, to host and display your live apps).
  • Affirmative Consent: When you authorize the remote MCP connector (mcp.vibelaunch.live/mcp) within supported third-party tools like Claude and, when available, future integrations such as ChatGPT, to publish on your behalf, we process that data based on your explicit consent, which you can revoke at any time.
  • Legitimate Interests: We process Technical and Usage Logs and privacy-conscious Product Analytics based on our legitimate business interest in protecting our systems, debugging technical issues, improving usability, and preventing fraudulent or malicious activities.
  • Legal Compliance: We may process limited records when necessary to comply with law, respond to valid legal requests, and protect the Services.

4. Third-Party Processors We Share Data With

GlintHQ LLC does not sell, rent, or trade your personal data to data brokers or advertisers. To host and run the Services, we share limited data with the following infrastructure sub-processors:

ProcessorWhat They DoData SharedPrivacy Policy
Supabase, Inc.Secure database, authentication management, and row-level security.Account profiles, authorization tokens, and metadata.supabase.com/privacy
Cloudflare, Inc.DNS, security firewalls, email routing, and edge worker hosting.Web traffic logs, IP addresses, and MCP payloads.cloudflare.com/privacypolicy
Google LLCSocial login authentication via OAuth 2.0.Google account identity token and profile confirmation.policies.google.com/privacy
Anthropic, PBCAI API processing to parse, organize, and split multi-file app uploads.Code payloads submitted by users for parsing and structuring.anthropic.com/privacy
OpenAI, L.L.C.Future AI connector integrations and contextual parsing.Code payloads submitted for optional ChatGPT connector workflows.openai.com/policies/privacy-policy
PostHog, Inc.Product analytics and session replay to help us understand usage and improve the product. Session recordings mask input contents. Data is hosted in the EU.Product usage events, page views, browser/session metadata, and masked session replay.posthog.com/privacy

5. How We Handle Artificial Intelligence (AI) Processing

VibeLaunch uses generative AI APIs (specifically Anthropic and OpenAI) to help parse multi-file pastes into clean, organized, and deployable file structures. GlintHQ LLC does not use your published code or apps to train proprietary machine learning models. Furthermore, we interact with Anthropic and OpenAI exclusively through commercial developer API channels. Under their enterprise terms, these processors are contractually prohibited from using your data payloads to train their foundational models.

6. Cookies and Storage

VibeLaunch uses "strictly necessary" cookies and local storage tokens managed by Supabase to verify your identity and keep you logged into your account. We do not use advertising cookies, third-party marketing beacons, or cross-site retargeting tags. When PostHog analytics is enabled, PostHog may use cookies or local storage to recognize a browser session for product analytics and masked session replay. You can set your browser to block cookies or send a recognized Do Not Track signal; blocking essential session cookies will prevent you from signing in and using VibeLaunch.

7. Communications From Us

We send transactional emails essential to operating your account — for example, security alerts, support replies, and material updates to these legal documents. You cannot opt out of these because they are necessary to provide the Services.

We may occasionally send you product-update or feature-announcement emails. You may unsubscribe from these non-essential emails at any time by following the unsubscribe link in any such email, or by contacting hello@vibelaunch.live.

8. How Long We Keep Your Data (Retention)

We do not hold onto data longer than necessary. Our standard data retention schedule is as follows:

  • Account & Profile Data: Retained for as long as your account remains active. Upon a verified deletion request submitted to hello@vibelaunch.live, we will purge your profile records from our active databases as soon as practicable, typically within thirty (30) days.
  • Published Code & Content: Retained for as long as your application is hosted on the Services. If you delete an app or close your account, the associated HTML, CSS, JavaScript, and supporting files are removed from active servers and edge caches as soon as practicable, typically within thirty (30) days, subject to standard backup retention cycles.
  • Technical Edge Logs: Request logs containing masked IP data are automatically overwritten or anonymized after ninety (90) days.
  • MCP Operational Events: Retained as operational product records while the Free Preview is running. If your account is deleted, account-linked user IDs in these events are de-identified where our database relationships allow, while aggregate reliability and abuse-prevention records may remain.

9. International Data Transfers

GlintHQ LLC is based in Wyoming, USA, and our hosting servers are located in the United States. If you access our Services from outside the United States, your personal data will be transferred to, stored, and processed in the US. By using our Services, you understand and consent to this transfer. To ensure your data remains protected, our infrastructure partners utilize industry-standard security safeguards, including Standard Contractual Clauses (SCCs) and active certifications under the EU-U.S. Data Privacy Framework.

10. Your Data Rights

Regardless of where you live, GlintHQ LLC provides all users with straightforward control over their data. You have the right to:

  • Access & Export: Request a portable copy of the personal data we hold about you.
  • Correction: Ask us to update or correct inaccurate or outdated profile information.
  • Deletion ("Right to be Forgotten"): Request that we permanently delete your account and all associated live applications.
  • Opt-Out: Opt-out of data sales or targeted advertising. Since we do not sell data or run targeted ads, you do not need to take any action to prevent this.

To exercise these rights, please email us from your registered Google Account email address to hello@vibelaunch.live. We will verify your identity before processing the request to protect your account's security.

11. Children's Privacy

The Services are not designed for, or directed to, children under the age of sixteen (16). We do not knowingly collect personal data from anyone under 16. If you are a parent or guardian and believe your child has created an account on our platform, please contact us at hello@vibelaunch.live so we can immediately delete their data.

12. Security Disclosures

To safeguard your data, we use industry-standard security protocols, including Transport Layer Security (HTTPS/TLS) for all web traffic. Our database uses Supabase Row-Level Security (RLS) policies to ensure that authenticated users can only access their own files and deployment records, preventing cross-tenant data leaks.

Please note that we are an early-stage company operated by a single founder, meaning our security is built on secure, managed cloud provider configurations rather than dedicated internal security personnel. No method of online storage or transmission is 100% secure, and we cannot guarantee absolute security.

13. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to match changing laws or operational practices. If we make a material update, we will post the revised policy on this page, update the "Last Updated" date, and send a notification to your registered email address thirty (30) days before the changes take effect.