Vibideo Privacy Policy

Effective date: August 7, 2026 Last updated: September 17, 2026

This Privacy Policy explains how Vibideo ("Vibideo," "we," "us," or "our") collects, uses, and shares information when you use the Vibideo iOS app (the "App"). This policy is hosted at https://vibideo.app/privacy and linked from the App Store listing and from the in-app paywall and Settings screen.

If you do not agree with this policy, please do not use the App.

1. Who We Are

Vibideo is operated by Vigilainte Inc ("Vigilainte"). For any privacy question or request, contact us at support@vigilainte.com.

2. No Account Required: How We Identify You

Vibideo does not require you to create an account, and it does not collect your name, email address, or phone number to use the App. Instead, when you first install the App, we generate a random, anonymous identifier (a UUID) and store it in your device's Keychain. This identifier:

Because this identifier can persist across reinstalls and is used to link your activity, purchases, and content together over time, we treat it as personal data under applicable law, even though it is not directly tied to your name or contact details.

3. Information We Collect

3.1 Device Identifier

The anonymous install/Keychain identifier described in Section 2.

3.2 Usage and Analytics Data

We collect product-analytics data about how you use the App, including screens viewed, buttons tapped, onboarding quiz answers, feature usage (e.g., which generation mode you use), and paywall/purchase funnel events (e.g., viewing the paywall, starting a purchase, completing or abandoning a purchase). This data is tied to your anonymous identifier, not to your name or contact information.

3.3 Purchase and Subscription Data

When you buy a subscription or a one-time credit pack, the purchase is processed by Apple through the App Store. We and our subscription-management provider receive transaction-level data (e.g., product purchased, price, renewal status, entitlement/credit balance) needed to grant and track your in-app credit balance. We do not receive or store your payment card details: those are handled entirely by Apple.

3.4 User Content

"User Content" means the text prompts you write, the photos you upload, and the videos generated for you. We collect and process User Content in order to:

3.4.1 Photos of People, and Face Data

Vibideo can turn a photo into a video. You choose that photo yourself, from your own photo library, through Apple's system photo picker. The App has no access to your photo library as a whole, only to the specific image you pick, and it never opens the camera.

Some of those photos contain a person's face. To be explicit about what we do and do not do with them:

Because no face measurements are extracted, there is no separate "face data" for us to store or retain: what exists is the image file you uploaded and the video generated from it, both covered by Section 6 (Data Retention), and both deletable on request at support@vigilainte.com.

If a photo you upload shows someone other than you, you are responsible for having that person's permission. See the "Your Content" and prohibited-content sections of our Terms of Service.

3.5 Push Notification Data

If you allow notifications, we use a push-notification provider to alert you when a video generation is complete. This requires sharing your device's push token and anonymous identifier with that provider.

3.6 Attribution Data

We use a mobile measurement provider, AppsFlyer, to tell us which ad campaign (if any) led to your install, and whether people who install the App go on to use and buy. AppsFlyer receives your device's app-install and session information, a device identifier, your IP address, an anonymous app-user identifier we generate, and a small, fixed set of app events: that an account was created, and that a first video generation finished successfully. It does not receive your prompts, your photos, or your generated videos.

If you install the App via an Apple Search Ads campaign, Apple also provides us with an attribution token that tells us which ad campaign led to your install.

Install attribution is not cross-app or cross-site tracking on its own: it tells us where an install came from, it does not let us follow you around other apps and websites. Where an advertising identifier is involved, that is controlled by the tracking prompt described in Section 3.7.

3.7 App Tracking Transparency (ATT) and Advertising

The App uses AppsFlyer, the Meta (Facebook) SDK, and the TikTok Business SDK to measure how well our ads perform and to attribute app installs and purchases to the ad campaigns that drove them. What those SDKs are allowed to do is controlled by Apple's App Tracking Transparency prompt, which the App displays:

In both cases, purchase events reported to AppsFlyer and Meta are sent server-side by our subscription-management provider, and we never report an amount you were not actually charged. The TikTok Business SDK is not used to report purchases or purchase amounts at all. You can change your choice at any time in iOS Settings → Privacy & Security → Tracking.

The TikTok Business SDK reports a small, fixed set of app-lifecycle events to TikTok so we can measure TikTok ad campaigns: that the App was installed, that it was opened, and whether it was opened again within two days of install. It does not receive your prompts, your photos, or your generated videos, and it is not used to report purchases or revenue. Where an advertising identifier is involved, it is shared only if you allowed tracking above.

3.8 Device Attestation

We use Apple's App Attest to verify that requests to our servers come from a genuine, unmodified copy of the App running on genuine Apple hardware. This is an anti-fraud/anti-abuse measure and relies on a device-generated cryptographic key. It does not collect personal information about you.

4. How We Use Information

We use the information above to: operate and provide the App's core features (generating, storing, and delivering your videos); manage your credit balance and purchases; understand and improve how people use the App; notify you when a generation finishes; detect and prevent fraud and abuse; and comply with legal obligations.

We do not sell your personal information, and we do not use your prompts, photos, or generated videos to serve you third-party ads.

5. Third-Party Service Providers

We share the categories of information described above with the following service providers, each acting in the role described. We recommend reviewing each provider's own privacy policy for details on how they handle data on our behalf.

Provider Role Data Involved Provider's Privacy Policy
Apple (App Store / RevenueCat) Processes your in-app purchases and subscriptions; RevenueCat manages subscription state and your credit balance. Anonymous identifier, purchase/transaction data Apple / RevenueCat
PostHog Product analytics: records app usage, screens, funnels, feature usage, onboarding answers, and purchase events. Anonymous identifier, usage events, person properties PostHog
OneSignal Sends push notifications (e.g., "your video is ready"). Anonymous identifier, device push token OneSignal
fal.ai Third-party AI infrastructure that processes your prompts and uploaded photos to generate your videos. Prompts, uploaded photos fal.ai
Cloudflare (R2 storage) Stores your uploaded input images and generated output videos. Uploaded photos, generated videos Cloudflare
Apple AdServices / Apple Search Ads Provides install-attribution data (which ad campaign, if any, led to your install). Attribution token Apple
Meta (Facebook SDK / Meta ads) Ads attribution and measurement: reports installs, app activity, and purchases to our Meta advertising account (see Section 3.7). Advertising identifier (IDFA: only with your ATT consent), anonymous app identifiers, app events including purchases Meta
AppsFlyer Mobile measurement partner: install attribution and ad-campaign measurement, and the single owner of Apple SKAdNetwork conversion values (see Sections 3.6 and 3.7). Advertising identifier (IDFA, only with your ATT consent), anonymous app identifier, IP address, install and session data, a fixed set of app events AppsFlyer
TikTok (TikTok Business SDK / TikTok ads) Advertising measurement for TikTok campaigns: reports app install, app open, and 2-day retention to our TikTok advertising account (see Section 3.7). Not used for purchases or revenue, and not used to write SKAdNetwork conversion values. Advertising identifier (IDFA, only with your ATT consent), anonymous app identifiers, app-lifecycle events TikTok

We may add or change service providers over time; if a change materially affects how your information is handled, we will update this policy.

6. Data Retention

Your uploaded photos and generated videos are retained on our servers so that you can access your library at any time within the App, and so that you can re-generate or extend a video you already made. They are held in a private storage bucket that is not publicly listable or browsable; the App reaches them through short-lived signed links. This applies equally to photos that contain a person's face, from which we derive nothing further (see Section 3.4.1). We do not currently offer in-app deletion of individual videos or photos. If you would like a specific piece of User Content, or all of your data, deleted, contact us at support@vigilainte.com and we will honor reasonable deletion requests within a reasonable time.

Analytics data and purchase records are retained as needed for product improvement, fraud prevention, financial record-keeping, and legal compliance, and may be retained in de-identified or aggregated form after your deletion request.

7. Children's Privacy

Vibideo is not directed to children under 13, and we do not knowingly collect personal information from children under 13 (or the relevant minimum age of digital consent in your jurisdiction). Users under the age of majority should use the App only with the involvement and consent of a parent or legal guardian. If you believe a child has used the App and provided us information without appropriate consent, contact us at support@vigilainte.com and we will take appropriate action, including deletion.

8. International Data Processing

Vibideo's backend and its service providers operate primarily in the United States, and content is delivered via Cloudflare's global edge network. If you use the App from outside the United States, your information, including your prompts, photos, and generated videos, will be transferred to, stored, and processed in the United States and potentially other countries where our providers operate. By using the App, you consent to this transfer.

9. Your Rights and Choices

Depending on where you live, you may have rights to access, correct, delete, or receive a copy of your personal information, or to object to or restrict certain processing (for example, under the EU/UK General Data Protection Regulation ("GDPR") or the California Consumer Privacy Act ("CCPA") and similar U.S. state laws). Because Vibideo does not collect your name or email address, we identify your data using your anonymous device identifier. To exercise these rights, contact us at support@vigilainte.com and, where possible, provide any details that help us locate your data (e.g., approximate signup date, device type).

You can also control certain data directly in the App or your device settings:

10. Security

We use reasonable administrative, technical, and organizational safeguards designed to protect your information, including transport encryption and device attestation to authenticate legitimate app traffic. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.

11. Changes to This Policy

We may update this Privacy Policy from time to time, for example as we add features or service providers. We will update the "Last updated" date above and, for material changes, provide additional notice (such as an in-app notice) where appropriate. Your continued use of the App after a change becomes effective constitutes acceptance of the revised policy.

12. Contact Us

Questions, requests, or concerns about this Privacy Policy or your data? Contact us at support@vigilainte.com.