Privacy Policy
Last updated: 30 September 2026
Vibee (vibee.one, the "Service") is operated by Daniel Rataj, Company ID (IČO) 71818871, registered at U měšťanského pivovaru 11, 170 00 Prague 7, Czech Republic, registered in the Czech trade licence register (the "Operator"). The Service is intended for businesses (see Terms of Service, Section 1); this policy explains what personal data the Operator processes as controller when you use vibee.one directly or through an AI assistant (ChatGPT, Claude or another MCP client) connected to your account.
1. Data we collect
- Account data – your e-mail address and a password hash (argon2). Required to create and secure your account.
- Content you create – database tables, rows, uploaded files, app configurations and endpoints that you or your AI assistant create in your account. This content may contain personal data of third parties (for example your customers); you are the controller of that data.
- App users – e-mail addresses and password hashes of people you allow to log in to your apps.
- Connection data – OAuth clients, authorization codes and access/refresh tokens (stored hashed) that link an AI assistant to your account.
- Payment data – if you buy an app extension, Stripe processes the payment. We store only the fact, time and subject of the purchase; card details never reach us.
- Technical logs – request logs (URL, status, timing, IP address) kept for operation and abuse prevention.
- Visitor statistics – on the public pages of vibee.one (the home page, guides, legal documents) we measure traffic with Umami: the page visited, the referring page, the browser and device type and the country; on the home page also which of its sections came into view and which buttons and links the visitor clicked. Umami uses no cookies and does not store IP addresses. Traffic is not measured in the admin or the account dashboard.
- Visits to your apps' public pages – for you as controller (see below and the DPA) we count visits to the public pages of your apps: the page, the day and the referring site or the link's utm_source. A visitor's IP address and browser are used only at the moment of the visit to compute a fingerprint with a random value that changes daily and is discarded; they are not stored and no cookies are used. Only anonymous daily totals are kept. Logged-in app users are not counted.
We do not receive your conversation with the AI assistant. The assistant sends the Service only the parameters of the tool it calls (for example a table definition or rows to insert).
If "Content you create" contains third parties' personal data, you are the controller of that data and the Operator is its processor within the meaning of Art. 28 GDPR. The terms of that processing (scope, duration, security, sub-processors, the incident procedure and termination of processing) are set out in the Data Processing Agreement (DPA), Annex 1 to the Terms of Service, publicly available at that link. For your own data covered by this section (account, payments, logs) the Operator is the controller.
2. Purposes and legal basis
- Providing the Service (contract performance, Art. 6(1)(b) GDPR): account, storage and serving of your tables, apps and files.
- Security and abuse prevention (legitimate interest, Art. 6(1)(f) GDPR): logs, rate limits, token handling.
- Improving the public pages (legitimate interest, Art. 6(1)(f) GDPR): anonymous visitor statistics.
- Billing and legal obligations (Art. 6(1)(c) GDPR): extension payments and accounting records.
3. Recipients
- Hetzner Online GmbH (Germany) – servers and object storage where the database and uploaded files live.
- Stripe Payments Europe, Ltd. – payment processing for app extensions.
- The AI assistant provider you connect (OpenAI for ChatGPT, Anthropic for Claude) – receives the results of the tools it calls on your behalf, under that provider's own privacy terms.
- Let's Encrypt – TLS certificates for custom app domains (the hostname only).
- Umami Software, Inc. (Umami Cloud, data stored in the EU) – visitor statistics for the public pages of vibee.one.
The same list of recipients, except Umami (which does not process your account's content), also constitutes the sub-processors under the DPA. We do not sell personal data and do not use it for advertising or profiling.
4. Retention
- Account, content and app users: for as long as your account exists. After account deletion, security backups are retained for up to 30 days and then permanently removed.
- If an account is blocked (for example for security reasons), you have 30 days to request an export of your content before it may be permanently removed.
- OAuth access tokens: 1 hour; refresh tokens: 30 days; authorization codes: 5 minutes. Revoked on password change.
- Web sessions: 14 days.
- Request logs: up to 30 days.
- Daily visit totals of apps: 400 days.
- Payment records: 10 years (accounting law).
5. Your controls
- Delete everything – Account → Delete account removes your account, all tables, rows, files, apps and tokens immediately and irreversibly. Export your content beforehand.
- Disconnect an assistant – remove the connector/app in ChatGPT or Claude, or change your password (revokes all tokens).
- Delete content selectively – through the admin dashboard or the MCP tools (drop_table, delete_rows, delete_file, delete_app).
- Export in a machine-readable format – CSV/JSON, at any time, in line with Regulation (EU) 2023/2854 (the Data Act); see Section 10 of the Terms of Service and Data Portability and Infrastructure.
- Access, rectification, portability, objection – write to info@vibee.one. You may also complain to the Czech Office for Personal Data Protection (ÚOOÚ).
6. Security
Data is encrypted in transit (TLS). Passwords are hashed with argon2id, tokens and API keys are stored hashed. Every account has its own database schema; identifiers are validated and values are always bound as parameters.
7. Cookies and browser storage
Vibee stores in your browser only what is strictly necessary to provide the Service you asked for. We use no advertising or analytics cookies, which is why we do not ask for consent or show a cookie banner.
- Login cookies –
sid(login to the vibee.one admin) andas_<app>(a user's login to a specific app). They hold only a random session identifier, are not readable by JavaScript (HttpOnly), last 14 days and are removed on logout. - Saved settings (localStorage) – the chosen light/dark theme and page language, and in apps with picking also the counts in progress, so they survive a page reload. This data stays in your browser and is not sent to the server.
- Visitor statistics – neither Umami (see Section 1) nor the visit counting of apps stores anything in your browser.
You can delete cookies and saved settings at any time in your browser settings; you will then be logged out and the settings return to their defaults.
8. Contact
Data protection requests: info@vibee.one.
Vibee