Privacy Policy - GDPR Compliance

Contents

  1. Preamble
    1. Legal basis for processing
    2. Protection of minors
  2. Identity of the data controller
  3. Personal data collected, used and processed
    1. Data actively collected
    2. Data from connected social platforms (TikTok, Instagram, YouTube)
    3. Videos generated and technical processing
    4. Technical logs
  4. Data recipients
  5. Data security
  6. Rights of data subjects
  7. Contact and Data Protection Officer (DPO)

1. Preamble

The purpose of this privacy policy is to inform users of our services in a clear, transparent and accessible manner about how their personal data is collected, used, stored, protected and, where applicable, shared.

In accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of individuals with regard to the processing of personal data (GDPR), we are committed to ensuring confidentiality, security and respect for your rights.

1.1 Legal basis for processing

In accordance with Article 6(1)(a) of the GDPR, the legal basis for all processing carried out by VibeCut is your explicit consent.

This consent is:

  • essential to use our services,
  • clearly and actively collected at the time of your registration or when connecting to third-party services (e.g. TikTok),
  • may be revoked at any time, without affecting the lawfulness of processing prior to such withdrawal.

You may withdraw your consent:

  • directly from your personal space,
  • or by sending a written request to the following address: contact@vibecut.net

1.2 Protection of minors

Use of the VibeCut platform is strictly reserved for persons aged 15 or over.

We do not intentionally collect or process personal data relating to minors under the age of 15, in accordance with Article 8 of the GDPR.

If we discover that a child under the age of 15 has transmitted personal data via our services, we will immediately take the necessary steps to:

  • delete the data concerned from our systems,
  • deactivate access to the account, if applicable.

Legal representatives (parents, guardians) may contact us at any time at the following address: contact@vibecut.net to exercise their rights in relation to the data of a minor.

2. Identity of the data controller

The controller of personal data, within the meaning of the General Data Protection Regulation (GDPR), is the entity that determines the purposes and means of processing personal data.

In the context of the use of our services, the data controller is:

  • Organization name: VibeCut
  • Legal representative / GDPR manager: Paul Noël-Bertin
  • Contact e-mail address: contact@vibecut.net

In accordance with Article 37 of the GDPR, VibeCut has appointed a Data Protection Officer (DPO), responsible for ensuring compliance with the applicable regulations and serving as a point of contact for any questions relating to personal data.

3. Personal data collected, used and processed

This section describes the types of personal data we collect, their purposes, and how long they are kept.

In accordance with Article 6(1)(a) of the GDPR, all processing carried out by VibeCut is based on your explicit consent, which conditions access to and use of our service.

Important: You may withdraw this consent at any time, without affecting the legality of the processing carried out prior to such withdrawal. Withdrawal can be made via your account settings or by written request to: contact@vibecut.net

3.1 Actively collected data

When you use our platform, you voluntarily provide us with the data required to provide the service:

Type of dataExamplesPurposeRetention period
Identification dataFirst name, last name, e-mail, passwordAccount creation, authentication, access to your personal spaceUntil account deletion or 6 months of inactivity
User preferencesCreators followed, preferred publication timesPersonalized experience, automated publication schedulingSame as above
Publication settingsTikTok, Instagram and YouTube login via OAuth, linked account identifiers and access tokensAutomatic publishing on your behalf via the official TikTok, Instagram (Meta) and YouTube (Google) APIsUntil you disconnect the account or delete your account

3.2 Data from connected social platforms (TikTok, Instagram, YouTube)

To publish your edited clips on your behalf, you may connect one or more social accounts via the official OAuth flow of each platform. We never see or store your platform password. For each connected account we process:

  • Public profile information: account identifier, username / channel name and avatar, used to show you which account a video will be published to.
  • OAuth access tokens: stored encrypted at rest and used solely to publish the content you approve and to read the basic profile above. We request the minimum scopes required (e.g. for Instagram, instagram_business_basic and instagram_business_content_publish).

Data obtained through the Instagram (Meta) and YouTube (Google) APIs is used only to provide the publishing feature you requested. It is not sold, and not used for advertising or transferred to data brokers. Our use of information received from the Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements, and our use of the Instagram platform adheres to the Meta Platform Terms.

Because VibeCut publishes to YouTube using the YouTube API Services, by connecting a YouTube account you also agree to the YouTube Terms of Service and the YouTube API Services Terms of Service, and the handling of your data by Google is governed by the Google Privacy Policy. You can review and revoke VibeCut's access to your Google data at any time via the Google security settings.

Revoking access and deletion. You can disconnect any account at any time from your VibeCut settings, which deactivates the connection and stops scheduled posts. You can also revoke access directly from the platform (for Instagram: Settings → Apps and websites; for YouTube / Google: your Google Account → Security → Third-party access). Revoking from Instagram triggers our automated deauthorization and data-deletion endpoints, which remove the associated tokens and connection from our systems.

4. Data recipients (third parties)

We do not sell your personal data and we do not disclose it to advertisers, data brokers, or for any AI/model-training purpose. Your data is shared only with the limited set of service providers (sub-processors) strictly necessary to operate the service. Each acts solely on our documented instructions, under a data processing agreement and appropriate safeguards.

Type of partyProviderData sharedGoogle user data?
Cloud database & authenticationSupabaseAccount data, user preferences, encrypted OAuth tokens and linked-account profile information (incl. Google / YouTube)Yes - raw, stored encrypted, for the publishing feature only
Application hostingVercelRequests processed in transit to run the applicationOnly in transit while serving your request
Payment processingStripeE-mail and billing details for subscriptionsNo
Product analyticsPostHogAggregated / anonymized product-usage data onlyNo
Publishing APIsTikTok, Meta (Instagram), Google (YouTube)The content you approve, sent back to the account you connected, to publish on your behalfN/A - data returned to its own platform

Google user data specifically. Raw Google user data (YouTube account profile information and OAuth tokens obtained via the Google APIs) is disclosed only to our infrastructure sub-processors above (Supabase for encrypted storage, Vercel for transmission) strictly to provide the publishing feature you requested, and is returned solely to Google's own YouTube API when you publish. Aggregated or anonymized Google user data is not shared with any party - our analytics provider (PostHog) never receives Google user data. We do not transfer Google user data to any other third party, and do not use it for advertising, sale, or AI/model training. Our use of information received from the Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

5. Data security

We implement appropriate technical and organizational measures to ensure a level of security appropriate to the risk, in accordance with Article 32 of the General Data Protection Regulation (GDPR).

4.1 Protective measures in place

  • Data encryption: All personal data is encrypted at rest and in transit via HTTPS (TLS 1.3)
  • Secure infrastructure: Services hosted on recognized cloud platforms with security certifications
  • Authentication and access control: Limited access with strong authentication systems
  • Monitoring and logging: Active monitoring for unauthorized access or abnormal behavior

6. Rights of data subjects

In accordance with the General Data Protection Regulation (GDPR), you have several rights regarding the personal data we process about you.

You can exercise the following rights at any time, by contacting us at: contact@vibecut.net

  • Right of access: Obtain confirmation and access to your personal data
  • Right of rectification: Request correction of inaccurate or incomplete data
  • Right to erasure: Request deletion of your personal data
  • Right to portability: Receive your data in a machine-readable format
  • Right to object: Object to processing based on legitimate interest
  • Right to withdraw consent: Withdraw consent at any time

7. Contact and Data Protection Officer (DPO)

If you have any questions about this privacy policy, exercising your rights, or the way in which we process your personal data, you can contact our Data Protection Officer (DPO).

Last update: August 5, 2026
We undertake to respond to any request within the timeframe stipulated by the GDPR (generally within 30 days).

Your preferences

Manage how VibeCut collects anonymous usage data on this device. Your choice is stored locally in your browser.

Anonymous usage data helps us improve VibeCut. You can opt out anytime.