Legal policy
Privacy Policy
How Vibeler collects, uses, discloses, retains, and protects personal information.
Draft for lawyer review: This page is a practical Vibeler policy draft, localized for Canadian requirements where relevant. It is not legal advice and should be reviewed by counsel before launch or enforcement.
Jump to section
1. Draft status and our role
This Privacy Policy is a practical operating draft for Vibeler and must be reviewed by a qualified Canadian privacy lawyer before launch or enforcement.
Vibeler may act as an organization that controls personal information for platform accounts, billing, security, support, analytics, and legal operations. For creator audience data, newsletters, gated access, and creator-directed communications, creators may also be accountable for their own collection, use, disclosure, consent, and notices.
2. Information we collect
- Account and profile information such as name, email, username, date of birth, profile details, authentication activity, and security settings.
- Creator Stage information such as handles, channels, themes, custom-domain setup, admins, capabilities, products, courses, pricing, coupons, events, posts, articles, newsletters, videos, podcasts, media, comments, reviews, and moderation actions.
- Audience activity such as follows, subscriptions, purchases, tips, course progress, product access, comments, reviews, RSVPs, newsletter subscriptions, notification interactions, and support requests.
- Payment and commerce information processed through Stripe, including transaction identifiers, subscription status, invoices, checkout and Connect status, payout-related status, chargeback/dispute signals, and limited payment-method summaries. Vibeler does not need to store full card numbers.
- Technical and security information such as IP address, device/browser data, session cookies, request logs, rate-limit signals, fraud indicators, media-processing logs, API proxy logs, and approximate location derived from network data.
- AI information such as prompts, selected context, generated drafts, usage and credit records, and related metadata for post, article, and newsletter generation.
3. How we use information
- Provide accounts, Stages, studio tools, public creator pages, private-channel access, paid entitlements, media upload/processing/playback, custom domains, comments, reviews, events, gamification, analytics, notifications, and newsletters.
- Process platform subscriptions, audience subscriptions, purchases, tips, coupons, booster packs, email coverage charges, disputes, refunds, chargebacks, and payout-related workflows through Stripe.
- Operate AI text tools through OpenAI or another disclosed AI provider and maintain AI credit balances and history.
- Send transactional emails, verification, recovery, invitation, receipts, support, legal notices, newsletter confirmations, unsubscribe messages, and creator-requested newsletters through email providers such as SendGrid.
- Secure the Services, detect fraud and abuse, enforce policies, prevent spam, preserve evidence, resolve disputes, and comply with legal obligations.
- Improve reliability, performance, routing, analytics, media processing, accessibility, product quality, and support using aggregated or de-identified information where appropriate.
5. Canadian privacy rights
PIPEDA and similar provincial private-sector privacy laws require accountability, identified purposes, consent, limiting collection, limiting use/disclosure/retention, accuracy, safeguards, openness, individual access, and challenging compliance where they apply.
You may request access to, correction of, or deletion of personal information, subject to identity verification and legal limits. Some information may be retained for security, fraud prevention, tax/accounting, payment disputes, legal compliance, backups, audit logs, or to protect other users.
6. Quebec, British Columbia, and Alberta considerations
If Vibeler serves users in Quebec, BC, or Alberta, additional substantially similar provincial privacy laws may apply to in-province activities. Vibeler should maintain a privacy governance owner, clear privacy practices, reasonable safeguards, complaint handling, and breach/confidentiality-incident procedures.
Quebec may require additional transparency about privacy governance, privacy impact assessments for some technology projects, confidentiality incident records and notices, clear privacy policies, privacy-by-default settings for some technology products, and information about out-of-Quebec communications. Lawyer review is required before launch in Quebec.
7. Cross-border processing
Vibeler and its subprocessors may process and store personal information in Canada, the United States, and other jurisdictions where service providers operate. When personal information crosses provincial or national borders in commercial activity, PIPEDA may continue to apply.
8. AI processing
When you use Vibeler AI features, Vibeler sends relevant prompts, context, and generated output to OpenAI as needed to provide text generation. Vibeler should not promise that AI data never goes to third parties. OpenAI's business/API commitments and privacy terms govern OpenAI's handling of data submitted to its services.
Do not put sensitive personal information, confidential information, payment information, government identifiers, health information, or children's information into AI prompts unless you have a lawful basis and understand the risks.
10. Security and retention
Vibeler uses reasonable administrative, technical, and organizational safeguards appropriate to the sensitivity of the information. No internet, email, payment, AI, or media service can be guaranteed completely secure.
Retention periods depend on the type of information and the reason it is held. Vibeler may retain records while your account or Stage is active and afterward as needed for operation, backups, payment/accounting, legal compliance, dispute resolution, safety, fraud prevention, and policy enforcement.
11. Contact and complaints
Legal, privacy, security, abuse, and copyright requests can be sent to [email protected]. Privacy-specific requests may also be sent to [email protected], and security reports may be sent to [email protected].