Privacy Policy

Last updated July 19, 2026

This Policy explains what personal data VibeCampus collects and how we use, keep, and transfer it, plus the rights and choices you have. It is written to match the actual implementation of the service, and it is updated whenever the service changes. We never sell your personal data.

Business information

Company
바이브캠퍼스 VibeCampus
Representative
HUHJUNMIN
Business registration no.
750-77-00505
Mail-order sales no.
2026-화성동탄-0575
Address
66 Dongtan-daero 1-gil, Dongtan-gu, Hwaseong-si, Gyeonggi-do, Republic of Korea
Email
support@vibecampus.app
Phone
010-7542-5163

Visitor data on sites members build

Visitor data collected by sites and apps our members build (form submissions, sign-ups, orders, bookings) does not pass through VibeCampus: it is saved straight into an external database the member owns and connected themselves (for example, their own Supabase account). VibeCampus does not newly collect or store this data; the controller is the member who built the site. Direct any access, correction, or deletion request to that site's operator.

Some visitor data stored through the previously offered platform-hosted backend (retired in 2026) may remain. New collection is shut off, and the residue is being destroyed on an automated schedule: form submissions are deleted once their stored retention deadline (about 180 days) passes, guest order/booking contact details are removed after 180 days, and activity logs older than 90 days are deleted. When the owning member deletes their account, their visitor data is deleted immediately.

1. General: controller, data we collect, purposes

The data controller is 바이브캠퍼스 VibeCampus (CEO HUHJUNMIN, 66 Dongtan-daero 1-gil, Dongtan-gu, Hwaseong-si, Gyeonggi-do, Republic of Korea). This Policy covers the VibeCampus website and its features. For any privacy request, contact support@vibecampus.app.

We collect the following. At signup we ask only for the minimum: email, nickname, and password.

• Account (required): email, nickname, password (stored only as a one-way hash), email verification code records, whether you agreed to the Terms, and whether you opted in to marketing

• Social login: the provider (Google, Kakao, Apple, GitHub, Naver), the provider's account identifier, email, and name or nickname

• Optional: phone number, secondary password (6-digit PIN, one-way hashed), profile (bio, avatar), referral code

• Content you create: posts, comments, projects, messages, team activity records, and the prompts, conversations, and attachments (images, PDFs) you submit to AI features

• Inquiries: name, email, and message content (support chat, contact form, inbound email)

• Cash-out requests only: legal name, payout (bank/recipient) details, requested amount and currency

• Payments: amount, currency, and PayPal transaction identifiers. We never collect or store full card numbers (PayPal processes them).

• Usage and security data: last-seen time, service usage records, AI usage metering (model, token counts and similar billing metadata), and IP addresses for security (used transiently for login protection and rate limiting; a one-way hash of the signup IP is kept to prevent referral fraud)

• External service keys you register (BYO keys: Anthropic, Supabase, etc.), stored encrypted with AES-256-GCM

• Usage statistics (only with your consent): visit and usage statistics collected by Google Analytics 4

Purposes: creating, authenticating, and protecting accounts; providing the service and its AI features; running the Credits economy including settlement and cash-outs; community and team features; responding to inquiries; preventing abuse; meeting legal obligations; and, only with consent, marketing and usage analytics.

Essential service messages (signup, account, password, payment notices) are always sent because the service cannot operate without them. Marketing (tips, events, offers) is sent by email or SMS only if you opt in; you can withdraw in account settings at any time and it stops immediately.

2. Generative AI notice

Prompts, content, and attachments you enter into AI features (build, edit, chat, image, video, music, speech, support) are transmitted to and processed by the third-party AI providers below to generate results.

• Anthropic (Claude): studio builds, edits and chat, live support, automated funding-campaign review, arcade assignment grading

• Google: Vertex AI (Imagen images, Veo video, Lyria music), Cloud TTS speech synthesis, and the Gemini API when certain support/verification features are enabled

• ElevenLabs: music generation prompts

• OpenAI: only when automated content-moderation or search-quality features are enabled (the text being checked)

• Failover routes: equivalent models via Google Cloud or Amazon Web Services are configured for outages and, if activated, process data for the same purposes

Training use: Anthropic's API and Google Vertex AI state that API inputs are not used to train their models by default. For other providers, training use follows each provider's policy. We do not train our own AI models on your inputs.

How to refuse: if you do not use the AI features, none of your input is sent to AI providers. If you use your own API key (BYO key), those calls are governed by your agreement with that provider. AI output can be inaccurate; your review responsibilities are set out in Section 6 of the Terms.

3. Retention and destruction

Principle: we destroy personal data without delay once its purpose is met. On account deletion, immediately: your email is irreversibly anonymized; name, real name, phone, profile and bio are deleted; stored BYO secret keys, connections, notifications and DMs are deleted; your public content is hidden; and all sessions are invalidated.

Statutory retention: records that the law requires us to keep (payments, transactions, cash-outs) are kept attached to an anonymized account shell, separated from identifying data, then destroyed after the period ends. We use them for no other purpose. Korean statutory periods:

• Records of contracts and withdrawal of offers: 5 years (Act on Consumer Protection in Electronic Commerce)

• Records of payment and supply of goods/services: 5 years (same Act)

• Records of consumer complaints or dispute resolution: 3 years (same Act)

• Tax records: the period set by tax law (generally 5 years)

Cash-out records (including legal name and payout details) are retained for those statutory periods and dispute handling even after withdrawal.

Automated destruction (runs daily): handled inquiries are deleted after 1 year; legacy visitor form submissions are deleted once their ~180-day deadline passes; guest order/booking contacts are removed after 180 days; legacy activity logs older than 90 days are deleted; BYO connection keys unused for 180 days are destroyed automatically.

Deleted content: content you delete is immediately hidden (soft delete) and may be retained internally for error recovery, dispute handling, and buyer protection for sold works. You can request permanent erasure of retained deleted content via Section 7, and we comply unless a legal duty requires retention.

We do not operate a separate login/access-log database; we keep only the minimum status data (such as last-seen time) needed for security and presence. Electronic files are erased using non-recoverable methods.

4. Processors and third-party sharing

We entrust processing to the companies below to run the service. Each processor receives only the minimum needed for its task.

ProcessorCountryTaskData processed
Vercel Inc.USAWeb hosting and deploymentData transmitted while you use the service
Neon Inc.USADatabase operationStored account, content, and transaction data
Fly.io, Inc.USA (processing location: Tokyo, Japan)Background build processingBuild prompts, generated output, member identifier
Anthropic, PBCUSAAI text/code generation, support, review assistancePrompts, content, and attachments submitted to AI features
Google LLCUSAAI media generation (Vertex AI), speech synthesis; Gemini API when enabled; statistics (GA4) with consentMedia/speech prompts, target text; usage statistics with consent
OpenAI, L.L.C.USAAutomated content moderation / search quality (only when enabled)Text being checked (nicknames, posts, etc.)
ElevenLabsUSAAI music generationMusic prompts
Amazon Web Services, Inc.USAAI failover route (only if activated)Prompts submitted to AI features
PayPal Holdings, Inc. and affiliatesUSA and othersPayment processing, settlement, refundsPayment amount, currency, transaction identifiers
Resend, Inc.USAEmail delivery (verification codes, notices, support replies, opted-in marketing)Email address, message content
Twilio Inc.USASMS delivery (if configured, opted-in users only)Phone number, message content
Intuition Machines, Inc. (hCaptcha)USASignup/login bot protection (if configured)IP address, browser data
Cloudflare, Inc. (Turnstile)USABot-prevention verification (if configured)IP address, browser data

We do not sell personal data, and we do not provide it to third parties beyond this processing, except where a lawful request (such as from law enforcement) requires it.

When you preview YouTube or Vimeo videos in the embed tool, those players load and their own cookie and privacy policies apply.

Operational alert webhooks (if configured) receive only minimal data with emails and names masked.

5. International transfers

To run the service, we transfer personal data abroad for entrusted processing and storage, disclosed here in accordance with Korea's Personal Information Protection Act (Article 28-8).

CategoryRecipient (contact)CountryData transferredRetention
Hosting / DBVercel Inc. (vercel.com), Neon Inc. (neon.tech)USAStored and transmitted account, content, and usage dataUntil account deletion or the end of the contract
Build processingFly.io, Inc. (fly.io)Japan (Tokyo region; US company)Build prompts, generated output, member identifierAs long as needed to process the build
AI generationAnthropic, PBC (anthropic.com) · Google LLC (google.com) · ElevenLabs (elevenlabs.io) · OpenAI, L.L.C. (openai.com, when enabled) · Amazon Web Services (aws.amazon.com, failover)USAPrompts, content, and attachments submitted to AI featuresAs long as needed to generate output (per provider policy)
PaymentsPayPal Holdings, Inc. and affiliates (paypal.com)USA and othersPayment amount, currency, transaction identifiersStatutory transaction-record period
MessagingResend, Inc. (resend.com) · Twilio Inc. (twilio.com)USAEmail address, phone number, message contentAs long as needed to deliver
Security checksIntuition Machines (hcaptcha.com) · Cloudflare (cloudflare.com)USAIP address, browser dataAs long as needed to verify
Statistics (with consent)Google LLC (policies.google.com/privacy)USAUsage statistics, device dataGoogle Analytics retention setting

Timing and method: transferred continuously over encrypted network connections (HTTPS/TLS) as you use the service.

Refusal and consequences: you may refuse these transfers by contacting support@vibecampus.app. Because they are essential infrastructure, refusing may limit your use of the service. Refusing the statistics transfer (GA4) never limits your use in any way.

Safeguards: encryption in transit end to end, data processing agreements (DPAs) with processors including standard contractual clauses, and the other safeguards required by law.

6. Cookies and similar technologies

Cookies we set ourselves are listed below. We use no advertising cookies.

NameTypePurposeLifetime
vc_sessionEssential (HTTP-only)Keeping you signed in30 days
vc_oauthEssential (HTTP-only)Anti-forgery state during social login10 minutes
vc_ghoauth · vc_sboauthEssential (HTTP-only)External connection (GitHub/Supabase) auth state10 minutes
vc_vcoauthEssential (HTTP-only)External connection (Vercel) auth state30 minutes
NEXT_LOCALEFunctionalRemembering your language choiceBrowser session
_ga · _ga_* (Google)Statistics (set only with consent)Visit and usage statisticsPer Google policy (up to about 2 years)

Statistics consent: choose in the banner on your first visit. Google Analytics 4 loads only if you agree (with IP anonymization). Declining never limits the service, and you can change your choice anytime via “Cookie settings” in the page footer.

Third-party cookies: PayPal on payment screens, hCaptcha and Cloudflare Turnstile on security checks (if configured), and YouTube/Vimeo players in embed previews may set their own cookies under their own policies.

Browser storage (localStorage etc.): your cookie choice (vc-consent), display settings such as theme and sound, local copies of studio and support conversations, funding campaign drafts, and dismissed-banner flags are stored in your browser, not on our servers. A service-worker app cache is used for offline support. You can clear all of it with your browser's data-clearing tools.

7. Your rights and how to exercise them

You may at any time request access, correction, deletion, restriction of processing, and withdrawal of consent. Directly in account settings you can: edit your profile and contact details, withdraw marketing consent (effective immediately), export your data (account, transactions, projects, posts as a JSON download), and delete your account (processed immediately).

For anything else (permanent erasure of retained deleted content, restriction requests, etc.), contact support@vibecampus.app. After verifying it is you (minimal checks such as confirming your account email), we act without undue delay within the periods set by law. You may also act through a legal representative or an authorized agent.

Exercising your rights never degrades your service. For complaints to supervisory authorities, see Section 10.

8. Security measures

We apply the following safeguards, all actually implemented:

• Passwords and secondary PINs are stored only as salted one-way hashes (scrypt), never in plain text. Sessions use HTTP-only, Secure, SameSite cookies, with remote session invalidation.

• All traffic is encrypted with HTTPS/TLS, with security headers (CSP, HSTS, X-Frame-Options) and sandboxed isolation of previewed content.

• Brute-force protection (login attempt limits and progressive delay), an optional secondary password (security PIN), and automated-attack checks (hCaptcha and similar).

• External service keys you register (BYO keys) are encrypted with AES-256-GCM; you can delete them in settings at any time and they are deleted on account closure. External connection keys (such as Supabase) are additionally destroyed automatically after 180 days of non-use.

• Least-privilege access; the source of for-sale builds is viewable/downloadable only by the owner and legitimate buyers; unauthorized scraping is blocked.

• The database runs on a managed cloud service whose backup and recovery mechanisms apply; content hashes are used to detect tampering.

No system is perfectly secure, so please use a strong, unique password (and the security PIN). If a breach occurs, we notify and report without delay as required by applicable law.

9. Children

VibeCampus is not directed at children under 14 (under 13 for US residents), and we do not intend to collect children's data. We do not currently collect dates of birth; signup requires confirming you are 14 or older by accepting the Terms.

If we learn that a child's data was collected without the required guardian consent, we delete it without delay. Parents and guardians: please contact support@vibecampus.app.

10. Privacy officer and remedies

Privacy officer: HUHJUNMIN (CEO) · contact: support@vibecampus.app. You may direct any privacy question, complaint, or remedy request there, and we will respond and act without undue delay.

For dispute mediation or counseling about privacy infringements, you can contact these Korean authorities:

• Personal Information Dispute Mediation Committee (privacy.go.kr / 1833-6972) · Privacy Infringement Report Center, KISA (privacy.kisa.or.kr / 118)

• Supreme Prosecutors' Office Cybercrime Department (spo.go.kr / 1301) · National Police Agency Cyber Bureau (ecrm.police.go.kr / 182)

Users outside Korea can also complain to their local supervisory authority (see the addenda in Sections 11 to 14).

11. EEA and UK addendum (GDPR)

This section applies to users in the European Economic Area and the United Kingdom. The controller is the company in Section 1. We have not appointed a DPO because we do not meet the mandatory designation criteria; direct all requests to the privacy officer in Section 10. No EU or UK representative is currently appointed.

Legal bases (GDPR Article 6): • Contract (Art. 6(1)(b)): providing your account, the service, AI features, and payments • Legitimate interests (Art. 6(1)(f)): security, fraud and abuse prevention, defending the service • Consent (Art. 6(1)(a)): marketing, statistics cookies • Legal obligation (Art. 6(1)(c)): transaction record-keeping, tax duties

You have the rights of access, rectification, erasure, restriction, data portability, and objection, and you may withdraw consent at any time (without affecting the lawfulness of processing before withdrawal). Exercise them as in Section 7.

We do not make decisions based solely on automated processing that produce legal effects on you or similarly significantly affect you.

Transfer safeguards: transfers from the EEA/UK to the Republic of Korea are covered by the European Commission's adequacy decision for Korea (2021) and the UK's adequacy regulations (2022). Transfers to processors in the USA and elsewhere are covered by data processing agreements incorporating Standard Contractual Clauses; some providers also hold EU-US Data Privacy Framework certification. See Sections 4 and 5 for the processor list.

Supervisory authorities: you may lodge a complaint with the authority of your member state (EEA list: edpb.europa.eu); in the UK, with the Information Commissioner's Office (ico.org.uk). If a breach poses a risk, we notify the supervisory authority within the GDPR deadline (72 hours as a rule) and take the required measures.

12. California addendum (CCPA/CPRA)

This section applies to California residents. We may fall below the CCPA's “business” thresholds (such as over $25 million annual gross revenue), but we honor the rights below for California residents regardless.

Categories of personal information collected in the last 12 months: • Identifiers (email, nickname, IP address) • Customer records (phone number; legal name and payout details for cash-outs) • Commercial information (purchase and transaction history) • Internet activity (usage statistics, only with consent) • Audio/visual information (content and profile images you upload) • Sensitive personal information limited to account login credentials, used only to provide the service. Sources, purposes, and recipients are as described in Sections 1 to 5.

We do not sell personal information, and we do not share it for cross-context behavioral advertising. A “Do Not Sell or Share My Personal Information” link is therefore not applicable. We do not sell or share the personal information of consumers we know to be under 16.

Rights: to know, access, correct, delete, limit use of sensitive personal information, and not to be discriminated against for exercising rights. Two ways to submit a request: (1) your account settings (data export, account deletion) or (2) email support@vibecampus.app. We verify requests via your account email; you may use an authorized agent.

13. Japan addendum (APPI)

This section applies to users in Japan. The purposes of use are published in Section 1 of this Policy.

Provision to third parties (processors) in foreign countries: your data is processed in the Republic of Korea (operations) and in the countries shown in the tables in Sections 4 and 5 (USA, Japan). Each processor is bound by contract and applies safeguards such as encryption. Information about those countries' data protection regimes is available in the survey materials published by Japan's Personal Information Protection Commission (ppc.go.jp).

Disclosure, correction, and suspension of use of retained personal data: request via account settings or email (no fee); we respond without undue delay. Security measures are as described in Section 8.

Contact: support@vibecampus.app. You may also consult Japan's Personal Information Protection Commission.

14. Users in China

We have no entity, servers, or dedicated representative in mainland China; the service is provided from the Republic of Korea. The Chinese-language interface is offered for convenience.

If you use the service from China, your personal data is transferred outside China (to Korea, the USA, and Japan) for processing. Recipients, items, purposes, and contacts are as shown in the tables in Sections 4 and 5. You can exercise access, correction, deletion, and account-deletion rights via account settings or email (Section 7).

If you do not agree to this offshore processing, you may stop using the service and request account deletion.

15. Effective date and change history

This revision takes effect on July 19, 2026.

• 2026-06-23: previous version in force

• 2026-07-19: full rewrite. Named processor and transfer tables; cookie and browser-storage inventory with consent-gated statistics; expanded generative-AI notice (ElevenLabs, OpenAI, and more); retention wording corrected to match actual operations; new EEA/UK, California, Japan, and China addenda

For material or unfavorable changes we give advance notice in the service. Previous versions are available on request at support@vibecampus.app.

VibeCampusNew build