Vibe Social (“we,” “us,” “our”) operates as an MCP (Model Context Protocol) server that connects your AI tools to your social media accounts. This policy explains what data we collect, how we use it, and your rights.
1. What We Collect
Account information. When you sign up, we collect your email address and payment information (processed by our payment provider — we don’t store card numbers).
OAuth tokens. When you connect a social media account, the platform issues an OAuth access token and refresh token. We store these tokens encrypted at rest. We never receive or store your social media passwords.
Usage data. We track API call counts per account for billing purposes — how many calls you make per month, broken down by platform. We do not log the content of those calls.
Technical data. Standard server logs: IP address, request timestamps, error codes. Retained for 30 days for debugging, then deleted.
2. What We Don’t Collect
- We don’t store your social media posts, DMs, comments, or analytics data. That data flows between the platform API and your AI — we’re the conduit, not the destination.
- We don’t read, analyze, or train on any content that passes through our server.
- We don’t sell, share, or monetize your data in any way beyond providing the service you signed up for.
3. How We Use Your Data
- OAuth tokens: To authenticate API requests to social platforms on your behalf, when your AI initiates an action through Vibe Social.
- Usage data: To enforce plan limits, generate your billing, and monitor for abuse.
- Email: To send account-related communications (billing, security alerts, service changes). No marketing emails without your explicit consent.
- Technical logs: To debug issues and maintain service reliability.
4. Third-Party Services
When you use Vibe Social, your AI sends requests to social media platform APIs (Instagram, YouTube, X, LinkedIn, TikTok, Threads, Bluesky, Facebook, Pinterest). Each platform has its own privacy policy governing how they handle API requests. We encourage you to review those policies.
We use third-party services for:
- Payment processing: Your payment information is handled by our payment provider and subject to their privacy policy.
- Hosting: Our servers are hosted on infrastructure with appropriate security certifications.
5. Data Security
- OAuth tokens are encrypted at rest using industry-standard encryption.
- All data in transit is encrypted via TLS.
- Access to production systems is restricted and logged.
- We don’t store social media content — if our systems were compromised, your posts, DMs, and analytics data aren’t there to take.
6. Data Retention
- OAuth tokens: Stored as long as your account is active and the social account is connected. When you disconnect an account, the token is deleted immediately.
- Usage data: Retained for billing and compliance purposes for 12 months after the billing period.
- Technical logs: 30 days, then deleted.
- Account data: If you delete your account, we delete all associated data within 30 days.
7. Your Rights
You can:
- Disconnect any social account at any time — the OAuth token is deleted immediately.
- Export your account data by contacting us.
- Delete your account and all associated data by contacting us.
- Access information about what data we hold about you.
If you’re in the EU/EEA, you have additional rights under GDPR including the right to data portability, the right to restrict processing, and the right to lodge a complaint with a supervisory authority.
8. Cookies
We use essential cookies for authentication and session management. No tracking cookies, no analytics cookies, no third-party advertising cookies.
9. Children
Vibe Social is not directed at children under 13. We do not knowingly collect personal information from children under 13.
10. Changes
If we make material changes to this policy, we’ll notify you by email at least 30 days before the changes take effect.
11. Contact
Questions about this policy? Email us at [email protected].