Privacy policy
Last updated: March 11, 2026
How VibeCraft works
VibeCraft provides dedicated machines with AI agents for business operations. Our architecture separates infrastructure management from customer data.
VibeCraft provisions your machine. After that, VibeCraft has no access to it. Software updates are handled automatically by the machine itself. There is no SSH, no remote login, no way for VibeCraft to access your machine. Your operational data stays on your machine. Your browser connects directly to your machine over HTTPS for all conversations, files, and agent interactions. This traffic does not pass through VibeCraft's servers.
What we collect
Account information. Name and email address, collected through WorkOS when you sign in.
Billing information. Processed by Stripe. VibeCraft stores your Stripe customer ID and subscription status. Full payment details are held by Stripe, never by VibeCraft.
Application form. Email address and optional message submitted when you request access.
Machine metadata. Server status, IP address, region, and provisioning timestamps. This is infrastructure data only.
What we do not collect
VibeCraft does not collect, store, or access:
- Conversations between you and your agent
- Screenshots taken by the agent
- Files, documents, or data on your machine
- Secrets or API keys in your encrypted vault
- Audit logs of agent actions
- Agent memory or learned preferences
- The AI API key on your machine
Your browser connects directly to your machine over HTTPS for all of the above. VibeCraft's servers are not in this path.
Data on your machine
All operational data lives on your dedicated machine: conversations, screenshots, secrets, audit logs, and agent memory.
Secrets and API keys are encrypted with AES-256-GCM. The AI agent references secrets by name but never sees the actual values.
Automated backups run on every machine.
When you cancel, your machine and all data on it are permanently deleted at the end of your billing period. No data remains on VibeCraft's servers because it was never there.
AI usage
VibeCraft provides the AI API key used by your agent. The key is stored on your machine in an encrypted vault and is unique to your machine.
AI requests go directly from your machine to Anthropic. VibeCraft is not in this path. VibeCraft does not train AI models on your data. VibeCraft receives only aggregate usage telemetry (token counts, no content) for billing purposes.
Third-party services
VibeCraft uses the following services to operate the platform. None have access to data on your machine.
- WorkOS for authentication
- Stripe for billing and payments
- AWS for machine infrastructure (N. Virginia, US)
- Resend for transactional email
- Vercel for hosting vibecraft.so
Data residency
Your machine is hosted in the United States by default. All operational data stays in your machine's region.
EU and other regions are available for enterprise customers. Platform services (authentication, billing, hosting) are processed by Vercel, Stripe, and WorkOS. These services only handle account and billing data, not operational data from your machine.
Your rights
You have the right to:
- Access the account data VibeCraft holds about you
- Correct inaccurate account information
- Delete your account and associated data upon request
- Export data from your machine before cancellation
VibeCraft cannot provide copies of data from your machine because VibeCraft does not have access to it. You export your own data directly.
Data retention
Account data (name, email) is retained while your account is active and deleted upon request after cancellation.
Billing records are retained as required by law.
Machine data is deleted when your machine is deleted. There is no residue on VibeCraft's servers.
Contact
For privacy questions: privacy@vibecraft.so