Privacy Policy
Last updated June 27, 2026
vibery is a product of Vibery LLC (“vibery,” “we,” “us”). It is an agentic productivity platform: with your direction, AI “crew” agents track your development work and act on your behalf across the tools you connect. This policy explains what information we collect, how we use it, and the choices you have. vibery is in active alpha, so this policy will evolve as the product does.
By using vibery you agree to this policy. If you do not agree, please do not use the service.
1. Information we collect
Account and authentication (GitHub)
You sign in with GitHub. We receive and store your GitHub username, email address, and avatar, along with an access token used to act on your behalf. We request the scopes needed to read your repositories and pull requests and to run workflows you trigger (repo, read:org, user:email, workflow). Access tokens are stored encrypted at rest.
Connected Google account (optional)
If you choose to connect a Google account, you grant vibery access so your agents can work with your Google Workspace on your behalf — for example, drafting emails, managing calendar events and tasks, reading and editing documents and spreadsheets, and working with your Drive files. We store the resulting Google access and refresh tokens encrypted at rest. Connecting Google is entirely optional and you can disconnect at any time (see Your choices). How we handle Google data is described in Google user data below.
Early access / waitlist
When you request early access we record your GitHub username and, if you provide it, your email address, so we can manage the waitlist and contact you. This may be synced to a private spreadsheet we control.
Your provider API keys (bring-your-own-key)
You may supply your own API keys for third-party AI providers (such as Anthropic, OpenAI, or OpenRouter). These keys are encrypted at rest (AES-256-GCM) on our backend and are never stored in your browser. We use them only to make the model calls your agents perform on your behalf.
Your repositories and code
To turn your real work into game state, we read metadata about your repositories, commits, pull requests, and CI status. Your source code and files stay in your own workspace; they are sent to an AI provider only when you ask an agent to act on them. We do not send your code to our analytics provider.
Usage analytics and diagnostics
We collect product-usage and performance data (such as which features are used, AI token counts, latency, and error signals) to operate and improve vibery. Basic analytics are on by default and can be turned off in Settings. More detailed analytics that include prompt and response content are off unless you opt in. Strings that look like API keys or secrets are redacted before analytics are recorded.
Cookies and local storage
We use a session cookie to keep you signed in and a short-lived cookie to protect the Google connection flow against cross-site request forgery. In your browser’s local storage we keep an anonymous identifier for pre-sign-in analytics and your interface preferences (such as theme and layout). We do not use third-party advertising cookies.
2. How we use your information
- To provide, operate, and secure vibery and your station.
- To perform the actions you direct your agents to take on the services you connect.
- To turn your development activity into game progress and crew status.
- To manage early access and communicate with you about the product.
- To monitor reliability, debug problems, and improve features.
- To comply with legal obligations and enforce our terms.
We do not sell your personal information, and we do not use it for advertising.
3. How your information is shared
We share data only with service providers that help us run vibery, and only as needed to deliver the service you ask for:
- GitHub — authentication and the repository, commit, pull-request, and workflow data you connect.
- Google — when you connect a Google account, for the Workspace actions you direct (see below).
- AI model providers (such as Anthropic, OpenAI, OpenRouter, and Google’s Gemini) — to run the agent tasks you request, using your keys where you provide them.
- PostHog — product analytics and diagnostics.
- Hosting and infrastructure providers — to host the application and run your agents.
- Optional tool providers you enable (for example, web-search or web-rendering services) when an agent uses that capability.
We may also disclose information if required by law, to protect the rights and safety of vibery and its users, or in connection with a merger, acquisition, or sale of assets.
4. Google user data
vibery’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
When you connect a Google account, you may grant the following access:
- Gmail — to draft, organize, and send messages at your request.
- Calendar — to read your schedule and create or update events you ask for.
- Drive, Docs, and Sheets — to read, create, and edit the files and documents you direct your agents to work on.
- Contacts — to look up the people you want to email or invite.
- Tasks — to create and organize to-dos on your behalf.
We use this access only to provide and improve the user-facing features you direct. Specifically:
- We do not use Google user data for advertising.
- We do not allow humans to read your Google data, except (a) with your explicit consent, (b) where necessary for security purposes (such as investigating abuse), (c) to comply with applicable law, or (d) where the data is aggregated and anonymized.
- We do not transfer or sell your Google data, and we use it only as needed to provide or improve the features you use.
You can review and revoke vibery’s access to your Google account at any time at myaccount.google.com/permissions.
5. Data retention
We keep your information for as long as your account is active or as needed to provide the service. We delete or anonymize it when it is no longer needed, when you delete your account, or as required by law. Encrypted credentials and connected-account tokens are removed when you disconnect the relevant service or delete your account.
6. Your choices and rights
- Analytics: turn basic or detailed analytics off in Settings → Privacy.
- Connected accounts: disconnect Google in Settings, and revoke access at myaccount.google.com/permissions; manage GitHub access in your GitHub settings.
- Access, export, or deletion: contact us to request a copy of your data or to delete your account and associated data.
Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA. To exercise any of these rights, email us at the address below.
7. Security
We protect your information with measures appropriate to its sensitivity, including encryption of credentials and connected-account tokens at rest and encryption in transit. No system is perfectly secure, but we work to safeguard your data and to limit who and what can access it.
8. Children
vibery is not directed to children. You must be at least 16 years old (or the age of digital consent in your country) to use the service. We do not knowingly collect information from children.
9. International users
vibery is operated from the United States, and your information may be processed there and in other countries where our service providers operate. Those countries may have different data-protection laws than your own.
10. Changes to this policy
We may update this policy as vibery evolves. When we make material changes, we will update the date above and, where appropriate, notify you. Your continued use of vibery after a change means you accept the updated policy.
11. Contact us
Questions about this policy or your data? Email privacy@vibery.gg.
Vibery LLC