Privacy Policy

Effective date: July 28, 2026

This policy explains what The Vibe (thevibe.chat) — operated under the trade name “The Vibe” by its founder, Masud Uddin Ahmed, pending formation of a corporate entity — collects, why, and the choices you have. We collect the minimum needed to run a safe, adults-only club network.

1. Location and geography

We never read GPS, device geolocation, or precise coordinates. Your browser's location permission is blocked by our security policy. We do not store street addresses, neighborhoods, or distance from other members.

Optional city (your choice): You may voluntarily add a city in Settings — selected manually from a curated list, never inferred from your device. City is off by default. You control whether it appears on your profile, who can see it (following connections only or all verified members), and whether it provides a gentle same-city nudge in tag-based discovery. Interest tags remain the primary matching signal. Optional city data is not used to promise dating outcomes, distances, or proximity matches. There is no distance display, map, or “nearby” feed.

Helper connections only (crisis): When room-safety systems detect severe distress, we surface appropriate confidential in-app helper resources using a tiered fallback: (1) a voluntary browser locale hint you send with your message (never GPS), (2) your connection’s country from our edge network (e.g. Cloudflare CF-IPCountry), or (3) a universal global directory at findahelpline.com. Country codes used for this purpose are not stored in our database and are separate from any city you choose to add to your profile.

Like most websites, our hosting provider (Cloudflare) may process network metadata (such as IP addresses) for security and delivery. We do not use that data to infer your city for profiling or discovery.

2. What we collect

  • Account data: email address and a hashed password (managed by Supabase Auth).
  • Profile data you provide: username, display name, bio, avatar choice, interest (“vibe”) tags, and optional voluntary city (city name, region/state, and country code — only if you add it in Settings).
  • Language preferences: your chosen app language (primary_native_language) for menus, numbers, and dates; optional practice languages (learning_slot_1, learning_slot_2); and, for clubs you lead, an optional club room_language_focus that steers tagged AI assistant replies. Browser locale may be used only as a client-side suggestion for first-time language selection — we do not auto-redirect you based on IP geolocation for language.
  • Location privacy preferences: whether to show your city, who may see it (following or members), whether to enable same-city discovery boost, and whether to hide your profile from people discovery.
  • Verification outcome only: right after email confirmation, you complete a one-time Didit identity check (government ID scan + live face match). We store only a verification status (VERIFIED_ADULT, PENDING, or REJECTED), a boolean verified flag, your age in years, and the verification timestamp. Didit sessions are linked to your account solely via your user ID (vendor_data). We do not store your government ID images, selfie or face biometrics, legal name, document numbers, date of birth, or raw webhook/decision payloads in our database or application logs. Didit processes ID and biometric data under Didit’s privacy policy as our verification processor.
  • Content: messages you send in clubs and private parlor chats with people (including channel placement, side-thread replies, and titled club posts), emoji reactions you add to club or parlor messages, Club Ledger mementos you create (title, summary, optional tags, and a link to the source message), AI-generated Club Highlights for clubs you belong to (shared among active members of that club only), optional thumbs on Highlights, product feedback you voluntarily submit, reports you file, votes you cast, optional club cover photos, and public feed posts you create (text, optional media, replies, quotes, and reposts), including likes and mentions on the public social feed.
  • Language Coach requests: when you tap Practice / Translate on a message, we send that message text (and your language preferences / club room focus) to our AI provider (Google Gemini) to return a private overlay with translation or practice phrasing, native-language glosses for recommended phrases, optional next-reply suggestions, key phrases, and soft immersion tips. Coach output is not posted back into the club chat and is not stored as a permanent coach history table — it is generated on demand for your client. If you choose Save phrase, we store the phrase you selected as a Club Ledger memento (title, summary, optional tags, optional link to the source message) shared with active members of that club only — the same memento system used elsewhere in clubs.
  • Public feed translation: when you tap Translate on a public feed post, we may send that post text to Google Gemini to return a translation into your app language. Translations may be cached on the post record so the same language request does not need to be regenerated.
  • Language Guide progress: if you open Language Guide practice with Luma (or another seated Language Guide), we store per-language practice progress on your account (language_progress): level band, score 0–100, path stage, assessment status, streak, optional goals, strengths, focus areas, alphabet/numbers flags, a short assessment summary, message counts, and a link to your private practice room and preferred Guide. We also store spaced-repetition review cards (language_review_items) scheduled automatically from placement and practice chat. Progress is keyed by you + language code (unified across Guides). Practice chats and assessment updates may be sent to Gemini to guide practice and quietly update that progress. Language Guides are entertainment practice support — not accredited education, certification, or professional advice.
  • Skill Practice Guide progress: if you open a private Practice Guide room for an allowed skill domain (for example music, chess, coding, cooking, art, writing, speaking, trivia, math puzzles, geography, sports rules, or debate), we store per-topic progress on your account (practice_progress): domain, topic, comfort level band, score 0–100, path stage, assessment status, streak, strengths, focus areas, a short assessment summary, message counts, and links to your private practice room and preferred Guide. We also store spaced-repetition retrieval cards (practice_review_items) with concrete prompts and answers generated for your topic (and refreshed from practice chat). Topic text is validated against ultra-strict filters that block medical, legal, financial, clinical mental-health, adult, weapons/crime, and high-stakes credential topics. Practice chats may be sent to Gemini for formative coaching, quiet progress updates, and card generation, typically in your app/native language. The default Guide character is Luma (also the Language Guide); Skill Practice Guides are entertainment / skill-rehearsal tools — not a school, not credentials, and not professional advice.
  • Club Practice links: club leaders may optionally enable a soft Practice link (domain + topic) so members can open their own private Practice Guide room related to the club’s focus. Practice scores and review cards stay private on each member’s account and are never used to admit, rank, grade, or remove members.
  • Practice sessions: when you run a practice session, we store the session itself (track, focus, objectives, difficulty, turn count, and XP earned) and a correction record for each of your own turns — what you wrote, the suggested correction, a short explanation, tags, and a verdict — plus your XP total, daily goal, current and best streak, and whether you have chosen to show practice progress to clubs. This is learning data about you, kept for you.
  • Club visibility: whether a club is a just-chat room (always private; opens in chat), private (invite/link only; a shareable preview page may show name, about, and member count), or public (may appear in topic-based Discover). Visibility is set at club creation and cannot be changed later, so members’ privacy expectations stay intact. Join approval is a separate, changeable setting.
  • Billing and payouts: your subscription status, any paid club memberships you hold, and — if you host a paid club or earn referral commission — earnings, commission, and payout records. Everything is keyed to Stripe identifiers. Card details, bank details, and identity documents are handled entirely by Stripe and never touch our servers. See section 6.
  • Push subscriptions: if you opt in, the browser push endpoint needed to deliver notifications. We also collect your in-app activity status (`is_active_in_app`) to prevent sending redundant notifications when you are actively using the Service, and your device's timezone to provide contextually relevant AI assistant interactions.
  • Follow connections: who you follow and who follows you, plus block lists (stored as relationship records between user IDs — we do not import your phone contacts).
  • Referral attribution: if you join via another member’s invite link, we store which member referred you (by user ID). We use it to grant your welcome bonus after ID verification and to calculate the referring member’s commission on platform revenue we later earn from your account. Your referrer sees commission amounts, never your activity or what you spent it on. We do not sell referral data.
  • Parlor preferences: whether you enable read receipts in private 1:1 parlor chats (on by default; you may disable in Settings).
  • Parlor read state: a per-thread “last read” timestamp so you and the other person can see unread counts and, if you both keep read receipts enabled, when messages were read.
  • Link previews (Open Graph): when a verified member shares a public http(s) link in club chat or Club Core, our servers may fetch publicly available page metadata (title, description, preview image, site name) to render a rich preview card — similar to major social apps. We do not log into the destination site, do not send your credentials, and block private / internal network addresses. Preview responses may be cached briefly to reduce repeat fetches. Preview images are loaded by your browser from the publisher’s CDN; we do not permanently store those images on our servers.

3. What we do not collect

  • Precise geolocation, GPS coordinates, street addresses, neighborhoods, or address book data.
  • Your government ID, legal name, document photos, or face/selfie biometrics (processed only by Didit under its privacy policy; we never persist them).
  • Third-party advertising identifiers or cross-site tracking profiles.

4. How we use your information

  • Operating clubs, parlor chats, governance, and interest-based discovery (with optional same-city boost when both members opt in);
  • Age-gating and keeping minors off the platform;
  • Generating AI assistant replies (recent club messages plus this club’s Ledger memory — digest, participant notes, mementos, and highlights — are sent to Google’s Gemini API to compose responses);
  • Generating Club Highlights after a club goes quiet (anonymized chat excerpts with temporary handles such as User_A, with emails/phones/IDs stripped, are sent to Gemini to produce shared recaps and update that club’s cumulative memory);
  • Safety review of AI outputs and member reports;
  • Running practice sessions — generating corrections, tracking XP and streaks, and scheduling review cards for you alone;
  • Processing subscriptions, paid club memberships, host payouts, and referral commissions through Stripe;
  • Operating follows, blocks, and handle-based lookup (blocked members are hidden from your discovery and cannot see your city);
  • Granting referral rewards (welcome bonus AI assistant sessions and Founding Member recognition for invited members; a lifetime commission on platform revenue for the referring member; a free Pro Host month at the published invite milestone; and optional Discover featuring for top monthly referrers who opt in) when invited members complete verification;
  • Delivering optional push notifications for club and parlor activity, ensuring you are not disturbed when actively using the app.
  • Providing timezone context to AI assistants for more natural and relevant interactions.
  • Enforcing published tier limits (club seats, clubs you may lead, daily AI assistant sessions) to keep the service sustainable.
  • Generating rich link preview cards from public Open Graph / Twitter Card metadata when verified members share web links in clubs (see section 2).

5. AI processing, privacy-first room safety, and helper connections

The Vibe is an 18+ social entertainment environment. Club messages you send may be transmitted to Google’s Gemini API to generate assistant replies and optional Club Highlights. Before any background Highlight synthesis, we strip direct personal identifiers (emails, phone numbers, account IDs) and replace member identities with temporary conversation handles for that request only. Highlight and memory records are partitioned by club ID — they are never merged across clubs.

Practice is private to the learner. Your practice turns are sent to Gemini to generate a correction and a score, and the result comes back to you alone. Corrections, session records, XP, and review cards are never posted into a shared thread, never shown to other members, never used to admit, rank, grade, or remove anyone from a club, and never sold. Your XP and streak stay private unless you turn on club sharing in Settings. Practice data is deleted with your account.

Automated background context evaluation (including Gemini analysis with recent conversation context) is deployed solely to help maintain safe, stable chat sessions. Support messages and hardship venting are not blocked for asking for help.

Private de-escalation: When severe safety or distress anomalies are detected, we resolve them through private, non-punitive, in-app de-escalation layouts that surface anonymous external help-seeking resource links. We do not build behavioral profiles of your emotional state for third parties.

Group chat privacy (Matrix Split): In clubs with multiple human members, a severe room-safety intercept on your message never writes that message to the shared chat history. Other members see only a generic notice that a participant stepped away — never your message, your name in connection with distress, or any mental-health signal. The intercept applies a room-local pause on your device only; it is not a permanent account ban and you may leave for the main dashboard and use other clubs.

AI Organizer (optional, off by default): A club leader may enable the AI Organizer for their social club. When enabled, recent messages from that club’s chat are periodically analyzed by Google’s Gemini API solely to suggest topic channels when conversation volume grows. Suggestions are advisory only: club leaders and moderators approve or dismiss every suggestion, and the AI never creates, renames, archives, moves, or deletes anything on its own (no automated decision-making with legal or similarly significant effect). The feature can be switched off at any time in club settings, and each club shows an “AI in this club” disclosure describing exactly which AI features are active. Practice studios never use the AI Organizer.

Club invite prompts (optional, off by default): A club leader may enable soft invite tools in General chat. When you tap Share, your device’s share sheet (or clipboard) may send a club link you choose to share. In-app invites stay inside The Vibe. For public clubs, you may optionally draft a post for the public feed — we never publish it without your confirm. Dismiss preferences are stored on your device. We do not scrape your address book or contact list.

Google applies additional safety filters to AI generation. When those filters block dangerous content, we may display confidential in-app helper connection resources. We do not use your private messages to train our own models.

6. Payments and payouts

We never receive or store your card number, bank account details, or identity documents. Stripe collects those directly from you and holds them on its own systems. What reaches our database is the unglamorous part: Stripe customer and account identifiers, subscription status, the amount and currency of a payment, the country and default currency of a payout account, and flags for whether charges and payouts are enabled.

Hosts and referral partners: if you charge for a club or earn referral commission, you complete Stripe’s identity verification (KYC) directly with Stripe via Connect Express. When you provide personal data in connection with payout setup, Stripe receives that personal data and processes it in accordance with Stripe’s Privacy Policy. Stripe is an independent controller for that data. We see only whether you passed, your country, and your default currency — never the documents you gave them. We also store when you accepted the payout disclosure (timestamp, IP, and disclosure version) so we can show we presented Stripe’s Connected Account Agreement before onboarding. The same connected account may receive both club membership payouts and referral transfers.

Legal basis: we process payment data to perform our contract with you — running your subscription, a club membership you bought, a payout you are owed. We retain transaction records because tax and anti-money-laundering law obliges us to.

Retention: transaction, earnings, and payout records are kept after you delete your account for as long as tax, accounting, anti-money-laundering, and platform-reporting law require (often several years; regimes such as DAC7 may apply). We remove the identifiers first, so what remains is a financial record that no longer identifies a person — the exemption in GDPR Article 17(3)(b) for legal obligations. Stripe may retain payment history and Connect KYC under its own controller obligations. How the money itself works is at Paid clubs, refunds, and payouts.

7. Processors we rely on

  • Supabase — database, authentication, and realtime infrastructure;
  • Didit — identity and age verification (ID images and biometrics are processed by Didit under Didit’s privacy policy; we receive and persist only the verification outcome and age in years);
  • Google (Gemini API) — AI assistant message generation, practice corrections, and safety classification;
  • Stripe — payments, host identity verification, and payouts (an independent controller for the identity and banking data it collects);
  • Cloudflare — hosting and network delivery.

8. What we don’t do

  • We do not sell or rent your personal information.
  • We do not run third-party advertising or ad trackers.
  • We do not use your private club messages or your practice corrections to train AI models.
  • We do not see, store, or share your payment card, bank, or identity documents.

9. Retention and deletion

Content is kept while your account is active. You may delete your account in Settings → Data & account (type DELETE MY ACCOUNT to confirm), or by emailing hello@thevibe.chat. We aim to complete verified self-service deletions immediately. Manual requests are handled within 30 days where GDPR applies and within 45 days where CCPA/CPRA or similar laws apply (extensions permitted by those laws when reasonably necessary).

What we remove promptly: your profile (username, display name, bio, avatar, vibe tags, verification flags, onboarding state), optional city and location preferences, follow connections and blocks, parlor threads and parlor messages (for both participants), push notification subscriptions, your practice sessions, corrections, XP, streaks, and review cards, your emoji reactions on club and parlor messages, Club Ledger mementos you created, your Highlight accuracy votes, product feedback you submitted, your per-club participant memory notes, referral attribution as a referred member, and billing linkage (active platform subscriptions and paid club memberships are cancelled immediately — if a cancel fails, deletion aborts so you are not charged after you are gone). We also delete or anonymize Stripe Customer objects we control on the platform account and on Connect accounts where we created them for your memberships.

What may remain (lawful exemptions): club messages you sent may stay visible to remaining members without your profile link (sender shown as “Former member”). Shared Club Highlights for clubs that continue without you may remain for remaining members (with your source message links cleared when applicable). Transaction, earnings, payout, and dispute records are kept where tax, accounting, anti-money-laundering, and platform-reporting law requires (including regimes such as DAC7 where applicable), stripped of the identifiers that tie them to you (section 6) — GDPR Article 17(3)(b). Safety reports you filed may remain as de-identified case records (reporter identity and free-text details cleared) for establishment or defence of legal claims and platform safety (Article 17(3)(e)). We keep a non-identifying deletion audit row (hashed identifiers only) to demonstrate we processed the request.

Stripe as independent controller: if you onboarded for host or referral payouts, Stripe Connect Express KYC and banking data stay with Stripe under Stripe’s retention and privacy rules. We remove our payout-account linkage; we do not delete Stripe’s Express account from under their books. Stripe may also retain payment history after Customer deletion or redaction where AML and tax law require it. See Stripe’s Privacy Policy.

Before you delete: if you lead a club that still has other active members, disband it from Club → Settings first (disbanding cancels members’ paid subscriptions so they are not charged for a closed club). Solo-led clubs you lead are closed automatically when you delete your account. Unpaid referral commission and unpaid host earnings still in clearing are forfeited — finish Stripe payouts first if you want that money (see Refunds & payouts). We email a deletion confirmation to the address on the account.

10. Your rights

Depending on where you live (including under the New York SHIELD Act and, where applicable, GDPR/CCPA-style laws), you may have rights to access, correct, export, or delete your data, and to object to certain processing. Contact hello@thevibe.chat to exercise them.

You do not have to ask us for the two most common ones. In Settings → Data & account you can download everything we hold about you as a JSON file — profile, messages you sent, club memberships, billing and payout records, practice sessions and corrections, notification endpoints, and reports you filed — and you can delete your account outright. The export leaves out two things: card and bank data, because Stripe holds it and we never do, and messages other people wrote, because that content is their personal data and not ours to hand over.

11. Security

Data is protected with encryption in transit, row-level security in our database, secret-scoped server APIs, and least-privilege service keys. No system is perfectly secure; we will notify affected users of any breach as required by law.

12. Children and AI assistants

The Service is not for anyone under 18. Immediately after email confirmation — before profile onboarding or any app features — you must pass mandatory document-based age verification (Didit KYC: government ID + live face match). The Vibe is operated from the United States and applies this 18+ gate worldwide. We delete accounts found to belong to minors. Every AI assistant and practice guide is written by us and written as an adult; members cannot create AI characters, so there are no user-submitted personas to review and no child or teen characters on the Service. AI assistants are always labeled as artificial intelligence.

13. Changes and contact

We will announce material changes in-app or by email 14 days in advance. Questions: hello@thevibe.chat · The Vibe (d/b/a of Masud Uddin Ahmed), United States.