Privacy

Privacy policy

This is a document about you, so it should be readable. Here is what vibegraph.ai stores, who else can see it, and how to get rid of it.

Last updated September 16, 2026

Who we are

vibegraph.ai is built and run by Raizen Labs LLC, an Arizona limited liability company. In this policy, "we" and "us" mean Raizen Labs LLC, and "your vibegraph" means the identity, brand and component content you build in the app.

Questions, requests and complaints go to privacy@vibegraph.ai, and a person reads them.

The short version

  • What you type and upload is stored on our servers, encrypted in transit and at rest, and scoped to your account.
  • No AI provider trains on your content. We pin that setting on every single request.
  • We never log what you write to an AI feature, or what it writes back.
  • Connected AI tools read only what you grant them, read-only, and every read is logged where you can see it.
  • Delete your account and your content goes with it.
  • We do not sell your data, and there are no advertising trackers on this site.

What we collect

Only what the product needs to work. There is no hidden collection and no profile built about you for anyone else's benefit.

  • Your email address, from the sign-in link or from Google if you choose to sign in with Google. Google sign-in also passes us your name and profile picture when your Google account has them.
  • What you write and upload: assessment answers, documents you upload, and the words and choices that make up your identity core, your brands and your components.
  • Purchase records. Stripe processes the payment and we never see or hold your card number. We keep Stripe's customer and payment identifiers and the fact that you bought an unlock.
  • Operating records for AI features: which feature ran, which model answered, how many tokens it used and what it cost. Never the prompt, and never the response.
  • A read log for connected tools: which tool read which entry of your vibegraph, and when.
  • Ordinary server and security logs kept by our hosting provider, such as IP addresses and request times.

Cookies

There are no analytics cookies, no advertising cookies and no third-party trackers on vibegraph.ai. The cookies we set are the ones that keep you signed in, and, while the pre-launch gate is on, one that remembers you arrived through a bypass link. Nothing follows you off this site.

How your vibegraph is stored

Your content is stored in conventional server-readable form, protected by encryption in transit and at rest and by row-level access control that scopes every row to the account that owns it.

We want to be plain about the limit of that: vibegraph.ai does not offer zero-knowledge encryption today. We hold your content in a form our systems can read, which is what makes generation, search and serving work. We will describe the hosted builder as zero-knowledge only when it actually is.

If server-readable hosting is not acceptable for your situation, the open framework at vibegraph.md is free and file-based, and you can keep your vibegraph entirely on hardware you control. That is why it ships open.

AI processing, and why no one trains on you

AI features send the content they need to OpenRouter, which routes the request to the model provider that answers it. Every request we make carries a no-train data policy pinned to that request, on top of the same setting held at the account level. It is set in one place in our code that all AI calls pass through, so a feature cannot opt out of it by accident.

We do not log the content of those requests or responses anywhere. Our own records hold the feature name, the model, token counts and cost, which is what we need to keep the service running and to stop runaway spend.

Serving your vibegraph to AI tools

You can connect AI tools to your vibegraph so they read it directly. That connection is read-only. Nothing a connected tool does can write to, change or delete your vibegraph.

By default a connected tool sees your root file and the entries marked public and always, which is the part of your vibegraph meant to be read every time. Anything marked on-task, and anything private, stays invisible until you grant it to that specific tool on the Connect screen. Grants are per tool, not per account. Leaving something ungranted does not expose it by omission: it is simply not served.

Every read is written to your read log before the content is returned, so the log cannot miss a read. You can see that log and revoke any tool at any time on the Connect screen.

Who else processes your data

We keep this list short on purpose, and we do not sell your data or share it for advertising.

  • Supabase: database, sign-in and file storage.
  • Vercel: hosting and delivery of the site.
  • OpenRouter and the model providers it routes to: AI features only, under the no-train policy above.
  • Stripe: payment processing. Stripe holds your card details under its own privacy policy; we do not.
  • beehiiv: only if you subscribe to the newsletter, and only your email address and how you signed up.
  • Google: only if you choose to sign in with Google.

How long we keep it

Your content stays while your account exists. There is no silent expiry and no archive you cannot reach.

When you delete your account, we delete the files you uploaded and then delete the account itself, which cascades to your content, your grants and your read log. One record survives on purpose: the row that proves a purchase happened, with your user id removed from it, kept for financial and tax records. It is detached from you and grants no access to anything.

Our hosting and payment providers keep their own operational and financial records under their own policies and legal obligations.

What you can do

  • Export your whole vibegraph as plain files at any time. The export is yours to keep, with or without an account here.
  • Delete your account from your account settings, which runs the deletion described above.
  • Revoke any connected tool, or any single grant, on the Connect screen.
  • Unsubscribe from the newsletter using the link in any issue.
  • Ask us for a copy of your data, a correction, or deletion, by writing to privacy@vibegraph.ai. If you are somewhere with a data-protection law such as the EU, the UK or California, those rights apply to you and we will honour them regardless of where you are.

Children

vibegraph.ai is not for children. You need to be at least 16 to hold an account. If we learn that an account belongs to someone younger, we delete it.

Changes to this policy

When this policy changes, the date at the top changes with it. If a change materially affects what we do with your content, we will email the address on your account before it takes effect.