The short version
We collect only what it takes to run your blog: your sign-in email, your content, and the minimum technical logs to keep the service reliable. We do not sell data, we do not run ads, and your posts belong to you. Reads on hosted blogs are counted with respect for Do Not Track and Global Privacy Control.
What we collect
- Account. The email address you sign in with, used for one-time-code login and service notices.
- Workspace content. Your blog’s posts, media, settings, and version history.
- Access tokens. API and MCP tokens are stored only as hashes. Full tokens are shown once at creation.
- Billing. Payments are processed by Polar. We never see or store your card number.
- Operations. Short-lived technical logs from our hosting provider for security and debugging.
What we never do
- Sell, rent, or broker your data.
- Load advertising networks or third-party trackers on the app or marketing site.
- Read your content to train models. Agents you authorize access it over scoped tokens; that access is visible in your activity log.
Reader analytics on your blog
Hosted blogs count page views so you can see what resonates. Visitor identifiers are hashed, and requests carrying Do Not Track or Global Privacy Control signals are not counted. Newsletter subscriber capture is explicit-consent based, with IP and user agent stored hashed.
Providers
The service runs on Cloudflare (compute, database, and media storage) with Polar for payments and a transactional email provider for sign-in codes and service messages. Each provider processes data only as needed to deliver the service.
Your content and your exits
You own everything you publish. Your posts and media are readable back through the same typed API and CLI your agents use, so leaving is a read operation, not a negotiation. Ask us to delete a workspace and we remove its content; encrypted backups roll off on a fixed cycle.
Early access
vibecms is in public early access, and this policy will mature with the product. If a change materially expands what we collect, we will announce it on the site before it takes effect.
Contact
Questions or requests about your data: support@vibecms.dev.