Privacy Policy
Last updated: 2 October 2026
This Privacy Policy explains which personal data we process when you use vibeex.io and the app at app.vibeex.io (the “Platform”), what we use it for, with whom we share it and what rights you have. It applies to users worldwide; section 12 contains additional information under the laws of certain U.S. states.
1. Who is responsible?
The controller within the meaning of the General Data Protection Regulation (GDPR) is:
[to be completed in the dashboard settings]
[to be completed in the dashboard settings]
Represented by: [to be completed in the dashboard settings]
Email: support@vibeex.io
Representative in the EU (Art. 27 GDPR):
[to be completed in the dashboard settings]
You can reach us with privacy requests at support@vibeex.io.
2. How old do you have to be?
The Platform is only for people aged 18 and over. We do not knowingly collect data from minors. If we learn that an account belongs to a minor, we suspend it and delete the data unless we are required to retain it.
3. What data do we process?
- Account: name, email address, password (only as a secure hash), date of birth, language, profile information and profile pictures; if you sign in with Google or Apple, an identifier and the email address of that account.
- Age verification: from Veriff we receive the result of the check as well as your name and date of birth. Veriff processes ID images and biometric data; we do not store them.
- Purchases: purchased content and memberships, amounts, times, order numbers, wallet transactions and receipts. As tax evidence, we store your declared country of residence and the country derived from your IP address for each purchase.
- Usage: Creators you follow and subscribe to, likes, comments, chat messages, reports, lists and settings.
- Creators: additionally uploaded content, co-performers and their consents, payout details and tax self-certification (stored encrypted), revenue, the “real person” or “AI model” setting and the results of content review.
- Communications: emails you send us or replies to our emails, including attachments; we link them to your account to handle your request.
- Technical and security data: IP address, browser and device data, timestamps, a random device identifier (cookie “vibeex_device”), country and time of your sign-ins and security events. For this purpose we store IP addresses only as a truncated hash.
4. Where does the data come from?
You provide most data yourself, for example when registering, in your profile, when purchasing and in messages. Technical data is generated automatically when you use the Platform. From third parties we receive the result of the age verification (Veriff), the payment status (NOWPayments) and, if you sign in that way, information from your Google or Apple account.
5. What do we use the data for, and on what legal basis?
- Providing the Platform and processing purchases, receipts, payouts, support and the notifications you have enabled (Art. 6(1)(b) GDPR).
- Legal obligations such as youth protection and age verification, tax evidence and retention obligations (up to 10 years), obligations under the Digital Services Act and reporting obligations (Art. 6(1)(c) GDPR).
- Security and abuse prevention, such as binding sessions to your device, alerts about sign-ins on new devices, blocking misused devices, bot protection and checking whether a password is known from data breaches (Art. 6(1)(f) GDPR; Art. 32 GDPR).
- Biometric face matching during age verification only with your explicit consent (Art. 9(2)(a) GDPR), which you can withdraw at any time with effect for the future.
Automated content review (AI). Uploaded images, frames from videos and profile and preview images are automatically analyzed by an AI model via Cloudflare Workers AI, among other things for the number of people, nudity, indications that someone may be under 18, violence and visible contact details. The legal basis is our obligations regarding youth protection and under the Digital Services Act (Art. 6(1)(c) GDPR) and our legitimate interest in preventing illegal content (Art. 6(1)(f) GDPR). The AI can approve content; rejecting content or suspending an account is always decided by a human. No solely automated decision with legal effect within the meaning of Art. 22 GDPR takes place. We store the results and reviewed frames as long as the content exists.
6. Who do we share data with?
- Cloudflare, Inc. (USA): hosting, database, media storage, email receipt, automated content review (Workers AI) and protection against attacks.
- Veriff OÜ (Estonia): age and identity verification with ID and face match.
- NOWPayments: processing of cryptocurrency payments. We transmit the amount, order number and a neutral description. Transactions on public blockchains are inherently publicly visible.
- Resend, Inc. (USA): sending emails.
- Google Ireland Ltd. and Apple Distribution International Ltd.: only if you choose “Continue with Google” or “Continue with Apple”.
- Have I Been Pwned: anonymized password checks; only the first 5 characters of a hash value are transmitted.
- Push services of your browser if you enable push notifications; only an encrypted message without chat content is transmitted.
- Service providers engaged by a Creator to manage the Creator’s account; they see that Creator’s chats and content, not your payment or login details.
- Authorities and courts where we are legally required to, for example reporting child sexual abuse material to NCMEC and law enforcement.
- Acquirers in the event of a sale or restructuring of our business, subject to this Privacy Policy.
We do not sell personal data and do not share it for targeted advertising. Creators only see a Fan’s profile, messages, purchases from them and publicly visible interactions.
7. International transfers
Vibeex is a company based in the United States. Your data is therefore processed in the United States and, through our providers’ data centers, in other countries. For transfers from the EU, the EEA, the United Kingdom and Switzerland, we rely on the European Commission’s Standard Contractual Clauses or the recipient’s certification under the EU-U.S. Data Privacy Framework. You can request a copy of the safeguards.
8. Cookies and local storage
We use only strictly necessary cookies: for sign-in, the security device identifier, protecting sign-in with Google or Apple, and your chosen language (“vibeex_lang”). In your browser’s local storage we keep, for example, your confirmation of the age notice and caches for faster loading. We do not use tracking, analytics or advertising cookies.
9. How long do we keep data?
We keep account data as long as your account exists. After your account is deleted, we delete the data unless statutory retention obligations apply – for example up to 10 years for invoice, payment and tax data – or we need it to defend legal claims and as evidence for youth protection. Security logs are deleted after 90 days at the latest, support emails once the request is closed and after 3 years at the latest.
10. How do we protect data?
Connections are encrypted, passwords are stored only as hashes, payout and tax details are encrypted. Sessions are bound to your device; you can optionally enable two-factor authentication. No system is completely secure; please keep your login details confidential.
11. Your rights
You have the right of access, rectification, erasure, restriction of processing, data portability and to object to processing based on legitimate interests, as well as the right to withdraw consent at any time with effect for the future. You can change or export much of your data yourself in the settings and delete your account there. For anything else, write to support@vibeex.io; we respond within one month. You can also lodge a complaint with a data protection supervisory authority, in particular in the country where you live.
12. Information for residents of U.S. states
Residents of California and other U.S. states with their own privacy laws (e.g. Colorado, Connecticut, Virginia, Utah, Texas, Oregon) have the following rights: to know which categories and specific pieces of personal information we collect, use and disclose; to delete; to correct; to data portability; to opt out of the sale or sharing of personal information for targeted advertising and of profiling – neither takes place on Vibeex; to limit the use of sensitive personal information – we use it only to provide the Platform; and not to be discriminated against for exercising these rights.
In the past 12 months we have collected the following categories: identifiers (name, email, IP address, account ID); characteristics of protected classifications (age); commercial information (purchases); biometric information (face match by Veriff); internet and usage activity; approximate geolocation (country); audio and visual information (media uploaded by Creators); sensitive personal information (login credentials, government ID data via Veriff and information that may allow inferences about sex life, such as purchases). We do not sell any category or share it for targeted advertising. Sources, purposes and recipients are described in sections 4 to 6.
Send requests to support@vibeex.io. We verify your identity using your account and respond within 45 days. You may use an authorized agent. If we decline a request, you may appeal within 45 days and we will review it again.
13. Changes
We update this Privacy Policy when the Platform or the law changes. We will inform you of material changes in advance by email or in the app.