Privacy Policy

    Last updated: October 2, 2026

    1. Who this covers

    VibeCS ("we", "us") provides an AI customer support chat widget that website owners embed on their own sites. This policy covers two groups of people:

    • Customers: people who create a VibeCS account and set up a widget for their website.
    • Visitors: people who chat with a VibeCS widget on a customer's website.

    2. Information we collect from customers

    • Account details. Your email address and a password you choose, or your name and email address if you sign in with Google. We never see your Google password.
    • Website content. When you ask us to crawl your website, we fetch its publicly accessible pages and store their text so the chatbot can answer questions about your product.
    • Billing. Payments are processed by Stripe. We store your email address and your subscription status. We do not store card numbers.
    • Support messages. Anything you send us through the Help page, with your name and email address so we can reply.

    3. Information we collect from visitors

    When a visitor chats with a widget, we receive the messages they type, the website the widget is installed on, a random session identifier so the conversation holds together, and the visitor's IP address, which we use only for rate limiting and abuse prevention. We do not ask visitors for their name or contact details, and we do not set tracking cookies through the widget.

    Chat messages are sent to our AI provider to generate a reply (see section 5) and a copy of each exchange is kept in our logs so the customer can review how their chatbot is performing.

    4. How we use information

    • To provide the service: crawling your site, answering visitor questions, and showing you your chat logs.
    • To run your account: signing you in, processing payments, and emailing you about your subscription or a crawl.
    • To keep the service safe: rate limiting, detecting abuse, and debugging problems.
    • To improve the product, using aggregate usage statistics that do not identify individual visitors.

    We do not sell personal information, and we do not use visitor conversations to advertise to anyone.

    5. Service providers

    We rely on a small number of providers to run VibeCS. Each receives only what it needs to do its job:

    • Supabase hosts our database, authentication, and server functions.
    • Google generates chatbot replies from the crawled content and the visitor's question, and provides optional Google sign-in for customers.
    • Firecrawl fetches website pages when a customer requests a crawl.
    • Stripe handles payments and subscriptions.
    • Vercel hosts this website.

    We also use FullStory and Fathom for analytics on cs-vibe.com itself, so we can understand how the site is used. These run only on our own site, not inside widgets installed on customer websites.

    6. Google user data

    If you sign in with Google, we receive your name, email address, and profile picture from Google and use them only to create and identify your VibeCS account. We do not request access to your Gmail, Drive, contacts, or any other Google data. Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

    7. Retention

    • Account details stay for as long as your account exists.
    • Crawled website content is replaced on each re-crawl and deleted when you delete your account.
    • Chat logs are kept so customers can review their chatbot. Customers may ask us to delete the logs for their site at any time.
    • Support emails are kept for as long as needed to resolve the request.

    8. Your choices and rights

    You can update your email address, cancel your subscription, or delete your account by contacting us. Depending on where you live, you may have the right to access, correct, export, or delete the personal information we hold about you, or to object to how we use it. To exercise any of these rights, email us at the address below and we will respond within 30 days.

    If you are a visitor and want a conversation removed, contact the website where you used the widget, or contact us directly with the site name and the approximate time of the chat.

    9. Security

    Data is encrypted in transit and at rest with our hosting providers. Access to production systems is limited to the people who operate VibeCS. No method of storage is perfectly secure, so we cannot promise absolute security, but we will notify affected customers without undue delay if we learn of a breach involving their data.

    10. Children

    VibeCS is a business tool and is not directed at children under 13. We do not knowingly collect personal information from children. If you believe a child has provided us with information, contact us and we will delete it.

    11. Changes to this policy

    We may update this policy as the service changes. The date at the top shows the latest revision. For significant changes we will email customers before the change takes effect.

    12. Contact

    Questions about privacy or this policy: jack@cs-vibe.com, or use the Help page.