1 Who We Are
VibeGyor ("we," "our," "us") is operated by Viraa Technologies. We provide an application that helps creators discover trending topics and repurpose content they choose into platform-native posts, then publish those posts to the social platforms they connect. Our registered contact email is privacy@vibegyor.ai.
2 What We Collect
Account Information
When you sign up we collect your email address and name. Authentication is handled by Clerk, a third-party identity provider. We do not store your password.
Content We Process
When you select or provide a source — a trending topic, a link, a video URL, or a file — our AI generates platform-native drafts (post text, captions, images, voiceovers, and short videos) tailored to each platform. You are responsible for ensuring you have the rights to repurpose any content you submit. If your source is a video, we process its audio track (transcription and speaker analysis) and its frames (shot and face detection, used only to frame and crop clips — we do not identify individuals) to select and edit the best moments.
To avoid re-processing the same source twice, downloaded source media and the analysis artefacts derived from it (transcripts, clip segments) are cached on our servers for up to 30 days after last use, then automatically deleted. Generated videos are retained for a limited window that depends on your plan (2–15 days — see Section 6), after which the video files are permanently deleted; generated text drafts remain available in your account until you delete them or your account.
Payment Information
If you purchase a subscription or coin pack, payment is processed by Apple App Store / Google Play (via RevenueCat) on mobile, or Stripe on the web. These processors handle your card or billing details — we never see or store your full payment card number. We store only your subscription tier, purchase history, and coin balance so we can provide the features you paid for.
Social Platform OAuth Tokens
When you choose to connect a social platform (X/Twitter, LinkedIn, Instagram, Facebook, Threads, YouTube, TikTok, Reddit), we receive and store an OAuth access token from that platform to publish content on your behalf when you explicitly tap "Post."
Device Information
We collect your device's push notification token (via Expo) to send you job-completion notifications. This token is deleted when you sign out.
Usage Data
We collect basic usage logs (timestamps, API request types, error codes) for debugging and service improvement. These logs do not contain your content or social tokens.
Cookies & Local Storage
The VibeGyor web app uses strictly-necessary cookies and browser local storage to keep you signed in (managed by Clerk, our authentication provider) and to remember in-app preferences such as theme. We do not use advertising or cross-site tracking cookies.
3 How We Use Your Data
| Data | Purpose |
|---|---|
| Email / name | Account creation, authentication, support communications |
| Source content you select | Input to AI content generation pipeline |
| AI-generated drafts | Presented to you for review; published only on your explicit instruction |
| OAuth tokens | Publishing content to the connected platform when you tap "Post" |
| Post performance metrics | Showing you how posts published through VibeGyor performed (views, likes, comments) |
| Purchase history / coin balance | Providing the plan features and credits you paid for |
| Push notification token | Sending job-completion alerts to your device |
| Usage logs | Debugging, performance monitoring, service improvement |
We do not use your content or social tokens for advertising, training AI models, or any purpose beyond the above. We do not sell your data.
4 Social Platform Integrations
When you connect a social account, VibeGyor:
- Stores your OAuth access token and refresh token (encrypted, server-side only).
- Uses the token to publish content only when you explicitly initiate a post — we never auto-post.
- After you publish through VibeGyor, periodically retrieves the performance metrics of that post (views, likes, comments) so we can show you how it performed. Metrics are refreshed roughly every 6 hours and each retrieved statistic is kept for no more than 30 days.
- Does not read your followers, direct messages, contact lists, or any other account data beyond your basic profile/page/channel details (needed to show you where a post will go) and the post metrics above.
- Will immediately delete the token if you disconnect the platform via Settings → Connected Accounts.
The specific permissions (OAuth scopes) we request from each platform:
| Platform | Permissions requested |
|---|---|
| X / Twitter | tweet.write, users.read, offline.access |
| openid, profile, email, w_member_social | |
| pages_show_list, pages_manage_posts, pages_read_engagement, public_profile | |
| instagram_business_basic, instagram_business_content_publish | |
| Threads | threads_basic, threads_content_publish |
| YouTube | youtube.upload, youtube.readonly |
| TikTok | user.info.basic, video.publish, video.upload |
| submit, identity |
YouTube API Services
VibeGyor's YouTube integration uses YouTube API Services. By connecting your YouTube channel, you agree to be bound by the YouTube Terms of Service. Our use of information received from YouTube API Services adheres to the Google Privacy Policy.
What YouTube data we access, and why:
- Your channel details (channel name, handle, and avatar) — retrieved via
youtube.channels.list(mine=true, scopeyoutube.readonly) only to show you which of your own channels a video will be published to. - Video upload — we upload a video that you created and approved in the app to
your own channel via
youtube.videos.insert(scopeyoutube.upload), and store the resulting video ID/URL so you can find your post. We act only when you explicitly tap "Post" — we never auto-upload. - Statistics of videos you published through VibeGyor — retrieved via
youtube.videos.list(part=statistics) so we can show you how your post performed (view, like, and comment counts). These statistics are refreshed roughly every 6 hours and each retrieved statistic is stored for no more than 30 days. - Public YouTube content in the discovery feed — VibeGyor's trending feed displays publicly available YouTube videos (title, thumbnail, channel name, view count, publish date) retrieved with a YouTube API key. This public data is cached for a maximum of 24 hours, refreshed continuously, and expired entries are purged automatically. Playback happens in YouTube's own embedded player.
We do not access your subscriptions, watch history, comments, private analytics, or any other YouTube data, and we do not share YouTube data with third parties or use it for advertising or to train AI models.
Storage, retention & deletion of YouTube data:
- Your YouTube OAuth tokens are encrypted (AES-256-GCM) and stored server-side only.
- Public feed data (including any displayed statistics) is stored for at most 24 hours; statistics of your published videos are stored for at most 30 days; each is then permanently deleted.
- Channel details and published-video references are retained until you disconnect YouTube or delete your account, then deleted within 30 days.
- Disconnect any time in Settings → Connected Accounts → Disconnect, which immediately deletes the stored YouTube tokens from our servers.
- You can also revoke VibeGyor's access to your Google/YouTube account at any time via your Google security settings (https://security.google.com/settings/security/permissions).
5 Data Sharing
We share your data only with the service providers below, each strictly for the purpose stated. None of them may use your data for their own advertising, and none receive your social tokens or password.
- Social platform APIs — when you explicitly request a post, and to retrieve the performance metrics of posts you published through VibeGyor.
- AWS (Amazon Web Services) — our cloud infrastructure provider. Data is stored in the US (us-east-1).
- Neon — our managed PostgreSQL database provider (encrypted at rest, US region).
- Upstash — managed cache used to serve the trending feed quickly. Holds only public feed content, never your personal data.
- Clerk — handles authentication (email/name only).
- Expo — receives your push notification token only. No content or social tokens are shared.
- OpenAI — our primary AI provider. Receives the text of the source content you choose to repurpose (and, for images, the generated image prompt) to produce drafts. No account identifiers or social tokens are sent, and your content is not used to train their models.
- Anthropic — additional AI provider we may route some text-generation requests to, under the same conditions as OpenAI.
- ElevenLabs — voice synthesis provider. Receives the generated voiceover script text (never your voice or personal details) to produce AI narration.
- pyannoteAI — speech-analysis provider. Receives the audio track of a source video you choose to repurpose, solely to produce the transcript and speaker timing used for clip selection.
- Pexels / Pixabay — stock-footage providers. Receive only anonymous search keywords derived from your draft (e.g. "city skyline"), never your content or identity.
- Stripe — payment processor for web purchases. Receives your billing details directly; we never see your card number.
- RevenueCat / Apple App Store / Google Play — process in-app purchases on mobile and tell us which plan you're on.
We do not sell, rent, or trade your personal data to any third party for marketing purposes, and we do not allow any provider to use your content to train AI models.
6 Data Retention
| Data type | Retention period |
|---|---|
| OAuth access & refresh tokens | Until you disconnect the platform or delete your account |
| Generated videos | 2–15 days depending on your plan (Free 2 · Starter 7 · Creator 10 · Elite 15), then the video files are permanently deleted |
| Generated text drafts & job records | Until you delete them or your account |
| Source media & analysis artefacts (transcripts, clips) | Up to 30 days after last use, then automatically deleted |
| Post performance metrics (from connected platforms) | Up to 30 days per retrieved statistic |
| Public trending-feed content (incl. YouTube data) | Maximum 24 hours in cache |
| Purchase history / coin ledger | Until account deletion (billing records kept as required by law) |
| Push notification tokens | Until you sign out |
| Account information (email, name) | Until account deletion |
| Usage logs | 90 days |
7 Security
- OAuth tokens are encrypted with AES-256-GCM before being written to the database.
- All communication uses TLS 1.2 or higher.
- Our database runs on encrypted storage volumes (AWS / Neon PostgreSQL).
- Encryption keys are stored in AWS Secrets Manager, never in source code.
- We conduct periodic access reviews on who can access production systems.
No system is 100% secure. If you suspect your account has been compromised, contact us immediately at privacy@vibegyor.ai.
8 Your Rights and Choices
- Disconnect a social account — tap Settings → Connected Accounts → Disconnect at any time. The token is deleted immediately.
- Delete your account — email privacy@vibegyor.ai and we will delete all your data within 30 days.
- Access your data — request a copy of all data we hold about you by emailing privacy@vibegyor.ai.
- Correct your data — if any information is incorrect, contact us and we will update it.
- Opt out of notifications — turn off notifications in your device settings at any time.
If you are located in the EEA or United Kingdom, you have additional rights under GDPR / UK GDPR, including the right to lodge a complaint with your local data protection authority.
9 Children's Privacy
VibeGyor is not directed at children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with information, please contact us at privacy@vibegyor.ai and we will delete it promptly.
10 International Data Transfers
VibeGyor is operated by Viraa Technologies, registered in Australia. Our servers are located in the United States (AWS us-east-1). By using the app, you consent to your data being transferred to and processed in the United States.
11 Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you via an in-app notification and update the "Last updated" date at the top of this page. Your continued use of VibeGyor after the effective date constitutes your acceptance of the changes.
12 Contact Us
For privacy questions, data deletion requests, or any concern about how we handle your information:
Email: privacy@vibegyor.ai
Website: vibegyor.ai
We aim to respond to all privacy enquiries within 5 business days.