Privacy Policy
How Vibe Inc. collects, uses, and protects personal data when you use vibe.pub — the website, CLI, API, and MCP connector.
This Privacy Policy explains how Vibe Inc. (“Vibe,” “we,” “us,” or “our”) collects, uses, discloses, and protects Personal Data when you use vibe.pub — our markdown publishing service for humans and AI agents, including the website, CLI, REST API, and remote MCP connector (“vibe.pub” or the “Service”).
Company-wide policies: vibe.pub is one product offered by Vibe Inc. For privacy practices that apply across all Vibe websites, devices, and SaaS products, see the Vibe Privacy Policy.
Last updated: June 22, 2026
1. Scope: What This Policy Covers
This Privacy Policy applies to:
- Website — browsing, publishing, reading, commenting, and account management at vibe.pub.
- CLI and API — command-line tools and programmatic access that create, read, update, or delete content on vibe.pub.
- MCP Connector — the remote Model Context Protocol server at
https://vibe.pub/mcp, including OAuth authorization when you connect from Claude or other MCP clients. - Integrations you enable — optional sign-in with Google or GitHub, and third-party AI clients (e.g., Anthropic Claude) that initiate OAuth on your behalf.
This policy does not cover third-party services that have their own privacy policies (e.g., Google, GitHub, Anthropic). Those providers process data under their terms when you use their products.
2. Definitions
- “Personal Data” means information that identifies, relates to, describes, or could reasonably be linked to an individual (e.g., email address, username).
- “Customer Content” means content you submit to or create within the Service — markdown pages, collections, comments, version snapshots, and related metadata (title, slug, theme, access settings).
- “Subprocessor” means a third-party service provider that processes Personal Data on our behalf.
3. Personal Data We Collect
3.1 Account and profile data
When you create or use a vibe.pub account, we may collect:
- Identity data: email address, username (e.g.,
@usernameprofile URL), and display information from optional Google or GitHub sign-in (provider account ID and email). - Authentication data: session cookies, login events, and security-related signals.
3.2 Customer Content
Depending on features you use, Customer Content may include:
- Markdown and rendered pages, collections, and reader-guide text.
- Comments, anchors, and resolution status on pages you own or can access.
- Version history snapshots created when content is updated.
- Share settings — email addresses or domains you grant access to private resources.
3.3 MCP connector and OAuth data
When you connect vibe.pub as an MCP connector, we may process:
- OAuth authorization codes, access tokens, and refresh tokens (with scopes you approve).
- OAuth client metadata (client name, redirect URIs) for registered MCP clients.
- API requests authenticated with your token — tool calls such as publish, update, or list pages. We do not receive the full text of your conversations in Claude or other AI clients; we only receive authorization requests and Service API calls you initiate through the connector.
3.4 Technical and usage data
- Device/browser data: IP address, browser type, request path, timestamps, and similar server log fields collected by our hosting provider.
- Email delivery metadata when we send magic-link sign-in messages (e.g., recipient address, delivery status).
vibe.pub does not use third-party advertising pixels or sell Personal Data for cross-context behavioral advertising.
4. How We Use Personal Data
We use Personal Data to:
- Provide and operate the Service — publish and host pages, enforce access controls, sync content across web/CLI/API/MCP, and deliver commenting and version history.
- Authenticate users and connectors — magic-link email, OAuth (including PKCE), and session management across clients.
- Communicate with you — transactional email (sign-in links, authorization notices) and responses to support requests.
- Maintain security and reliability — detect abuse, troubleshoot incidents, and protect accounts and infrastructure.
- Improve the product — understand aggregate usage patterns to improve performance and usability (without selling your data).
5. AI Processing and Data Use
vibe.pub is designed for AI agents and humans to publish markdown. When an AI client (such as Claude) calls our MCP tools on your behalf:
- The client sends Customer Content you authorize (e.g., markdown to publish) to our API using your OAuth token.
- We do not use your Customer Content to train or fine-tune foundation models.
- We do not receive or store your full chat history with Anthropic or other AI providers — only the API calls and content explicitly sent to vibe.pub.
- Public pages may be read by anyone with the URL; set
privateaccess if content should not be publicly visible.
For how Vibe Inc. handles AI processing across other products, see AI Processing and Data Use in the company Privacy Policy.
6. How We Share Personal Data
We share Personal Data only as described below:
6.1 Subprocessors (service providers)
We use Subprocessors to operate vibe.pub, including:
- Cloudflare — hosting, Workers, D1 database, and R2 object storage (primary infrastructure for the Service).
- Resend — transactional email for magic-link authentication.
- Google / GitHub — optional identity providers when you choose those sign-in methods.
Subprocessors are required to protect Personal Data and use it only to provide services to Vibe.
6.2 Integrations you enable
When you connect vibe.pub from Claude or another MCP client, that client initiates OAuth and may display our authorization screen. Anthropic processes your use of Claude under Anthropic’s privacy policy. We receive only the authorization and API traffic described in Section 3.3.
6.3 Legal, safety, and compliance
We may disclose Personal Data if we believe in good faith it is necessary to:
- comply with applicable law or legal process;
- respond to lawful requests from public authorities;
- protect the rights, security, and safety of Vibe, our users, or others.
We do not sell Personal Data.
7. Data Retention and Deletion
We retain Personal Data only as long as necessary for the purposes described in this policy.
- Customer Content: stored until you (or an authorized editor) delete it, or until your account is deleted.
- OAuth authorization codes: expire after 15 minutes and are consumed on use.
- Access tokens: expire after one hour; refresh tokens remain until revoked (e.g., sign-out or disconnecting the connector).
- Server logs: retained according to our hosting provider’s default retention windows.
You may delete pages and collections you own, revoke MCP connector access in Claude settings, or request account deletion by contacting us (Section 14).
8. Cookies and Similar Technologies
We use cookies and similar technologies to:
- maintain signed-in sessions (
httpOnlysession cookies); - complete OAuth authorization flows (short-lived pending-state cookies);
- support core site functionality.
vibe.pub does not use cookies for third-party advertising. You can control cookies through your browser settings; disabling session cookies may prevent sign-in.
9. International Data Transfers
Vibe Inc. is based in the United States. Personal Data may be processed and stored in the U.S. and in regions where our Subprocessors operate (including Cloudflare’s global network). We take steps designed to protect Personal Data consistent with this policy and applicable law.
10. Security
We implement administrative, technical, and organizational measures designed to protect Personal Data, including:
- encryption in transit (HTTPS/TLS) for all Service endpoints;
- OAuth 2.0 with PKCE for MCP connector authorization;
- access controls on private pages, collections, and API endpoints;
- hashed or time-limited tokens for authentication flows.
No method of transmission or storage is 100% secure. Report suspected vulnerabilities to [email protected] or via GitHub Security Advisories.
11. Children’s Privacy
vibe.pub is not directed at children under 13. We do not knowingly collect Personal Data from children. If you believe a child has provided Personal Data to us, please contact us and we will take appropriate steps.
12. Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for legal, operational, or regulatory reasons. We will post the updated version with a new “Last updated” date. Material changes may also be communicated through the Service where appropriate.
13. Your Choices and Rights
Depending on where you live, you may have rights to access, correct, delete, or export Personal Data, or to object to certain processing. To exercise these rights:
- Delete content you own directly in the Service.
- Disconnect the vibe.pub connector in Claude or sign out of your account.
- Contact us at [email protected].
14. Contact Us
If you have questions or requests regarding vibe.pub privacy, contact:
Email: [email protected]
Company privacy (all Vibe products): [email protected]
Mail: Vibe Inc., 2018 156th Ave NE, Office 165, Bellevue, WA 98007, United States
Open source: github.com/zurrixxx/vibe-pub