Privacy Policy
Last updated July 19, 2026
This Policy explains what personal data VibeCampus collects and how we use, keep, and transfer it, plus the rights and choices you have. It is written to match the actual implementation of the service, and it is updated whenever the service changes. We never sell your personal data.
Business information
- Company
- 바이브캠퍼스 VibeCampus
- Representative
- HUHJUNMIN
- Business registration no.
- 750-77-00505
- Mail-order sales no.
- 2026-화성동탄-0575
- Address
- 66 Dongtan-daero 1-gil, Dongtan-gu, Hwaseong-si, Gyeonggi-do, Republic of Korea
- support@vibecampus.app
- Phone
- 010-7542-5163
Visitor data on sites members build
Visitor data collected by sites and apps our members build (form submissions, sign-ups, orders, bookings) does not pass through VibeCampus: it is saved straight into an external database the member owns and connected themselves (for example, their own Supabase account). VibeCampus does not newly collect or store this data; the controller is the member who built the site. Direct any access, correction, or deletion request to that site's operator.
Some visitor data stored through the previously offered platform-hosted backend (retired in 2026) may remain. New collection is shut off, and the residue is being destroyed on an automated schedule: form submissions are deleted once their stored retention deadline (about 180 days) passes, guest order/booking contact details are removed after 180 days, and activity logs older than 90 days are deleted. When the owning member deletes their account, their visitor data is deleted immediately.
1. General: controller, data we collect, purposes
The data controller is 바이브캠퍼스 VibeCampus (CEO HUHJUNMIN, 66 Dongtan-daero 1-gil, Dongtan-gu, Hwaseong-si, Gyeonggi-do, Republic of Korea). This Policy covers the VibeCampus website and its features. For any privacy request, contact support@vibecampus.app.
We collect the following. At signup we ask only for the minimum: email, nickname, and password.
• Account (required): email, nickname, password (stored only as a one-way hash), email verification code records, whether you agreed to the Terms, and whether you opted in to marketing
• Social login: the provider (Google, Kakao, Apple, GitHub, Naver), the provider's account identifier, email, and name or nickname
• Optional: phone number, secondary password (6-digit PIN, one-way hashed), profile (bio, avatar), referral code
• Content you create: posts, comments, projects, messages, team activity records, and the prompts, conversations, and attachments (images, PDFs) you submit to AI features
• Inquiries: name, email, and message content (support chat, contact form, inbound email)
• Cash-out requests only: legal name, payout (bank/recipient) details, requested amount and currency
• Payments: amount, currency, and PayPal transaction identifiers. We never collect or store full card numbers (PayPal processes them).
• Usage and security data: last-seen time, service usage records, AI usage metering (model, token counts and similar billing metadata), and IP addresses for security (used transiently for login protection and rate limiting; a one-way hash of the signup IP is kept to prevent referral fraud)
• External service keys you register (BYO keys: Anthropic, Supabase, etc.), stored encrypted with AES-256-GCM
• Usage statistics (only with your consent): visit and usage statistics collected by Google Analytics 4
Purposes: creating, authenticating, and protecting accounts; providing the service and its AI features; running the Credits economy including settlement and cash-outs; community and team features; responding to inquiries; preventing abuse; meeting legal obligations; and, only with consent, marketing and usage analytics.
Essential service messages (signup, account, password, payment notices) are always sent because the service cannot operate without them. Marketing (tips, events, offers) is sent by email or SMS only if you opt in; you can withdraw in account settings at any time and it stops immediately.
2. Generative AI notice
Prompts, content, and attachments you enter into AI features (build, edit, chat, image, video, music, speech, support) are transmitted to and processed by the third-party AI providers below to generate results.
• Anthropic (Claude): studio builds, edits and chat, live support, automated funding-campaign review, arcade assignment grading
• Google: Vertex AI (Imagen images, Veo video, Lyria music), Cloud TTS speech synthesis, and the Gemini API when certain support/verification features are enabled
• ElevenLabs: music generation prompts
• OpenAI: only when automated content-moderation or search-quality features are enabled (the text being checked)
• Failover routes: equivalent models via Google Cloud or Amazon Web Services are configured for outages and, if activated, process data for the same purposes
Training use: Anthropic's API and Google Vertex AI state that API inputs are not used to train their models by default. For other providers, training use follows each provider's policy. We do not train our own AI models on your inputs.
How to refuse: if you do not use the AI features, none of your input is sent to AI providers. If you use your own API key (BYO key), those calls are governed by your agreement with that provider. AI output can be inaccurate; your review responsibilities are set out in Section 6 of the Terms.
3. Retention and destruction
Principle: we destroy personal data without delay once its purpose is met. On account deletion, immediately: your email is irreversibly anonymized; name, real name, phone, profile and bio are deleted; stored BYO secret keys, connections, notifications and DMs are deleted; your public content is hidden; and all sessions are invalidated.
Statutory retention: records that the law requires us to keep (payments, transactions, cash-outs) are kept attached to an anonymized account shell, separated from identifying data, then destroyed after the period ends. We use them for no other purpose. Korean statutory periods:
• Records of contracts and withdrawal of offers: 5 years (Act on Consumer Protection in Electronic Commerce)
• Records of payment and supply of goods/services: 5 years (same Act)
• Records of consumer complaints or dispute resolution: 3 years (same Act)
• Tax records: the period set by tax law (generally 5 years)
Cash-out records (including legal name and payout details) are retained for those statutory periods and dispute handling even after withdrawal.
Automated destruction (runs daily): handled inquiries are deleted after 1 year; legacy visitor form submissions are deleted once their ~180-day deadline passes; guest order/booking contacts are removed after 180 days; legacy activity logs older than 90 days are deleted; BYO connection keys unused for 180 days are destroyed automatically.
Deleted content: content you delete is immediately hidden (soft delete) and may be retained internally for error recovery, dispute handling, and buyer protection for sold works. You can request permanent erasure of retained deleted content via Section 7, and we comply unless a legal duty requires retention.
We do not operate a separate login/access-log database; we keep only the minimum status data (such as last-seen time) needed for security and presence. Electronic files are erased using non-recoverable methods.
4. Processors and third-party sharing
We entrust processing to the companies below to run the service. Each processor receives only the minimum needed for its task.
| Processor | Country | Task | Data processed |
|---|---|---|---|
| Vercel Inc. | USA | Web hosting and deployment | Data transmitted while you use the service |
| Neon Inc. | USA | Database operation | Stored account, content, and transaction data |
| Fly.io, Inc. | USA (processing location: Tokyo, Japan) | Background build processing | Build prompts, generated output, member identifier |
| Anthropic, PBC | USA | AI text/code generation, support, review assistance | Prompts, content, and attachments submitted to AI features |
| Google LLC | USA | AI media generation (Vertex AI), speech synthesis; Gemini API when enabled; statistics (GA4) with consent | Media/speech prompts, target text; usage statistics with consent |
| OpenAI, L.L.C. | USA | Automated content moderation / search quality (only when enabled) | Text being checked (nicknames, posts, etc.) |
| ElevenLabs | USA | AI music generation | Music prompts |
| Amazon Web Services, Inc. | USA | AI failover route (only if activated) | Prompts submitted to AI features |
| PayPal Holdings, Inc. and affiliates | USA and others | Payment processing, settlement, refunds | Payment amount, currency, transaction identifiers |
| Resend, Inc. | USA | Email delivery (verification codes, notices, support replies, opted-in marketing) | Email address, message content |
| Twilio Inc. | USA | SMS delivery (if configured, opted-in users only) | Phone number, message content |
| Intuition Machines, Inc. (hCaptcha) | USA | Signup/login bot protection (if configured) | IP address, browser data |
| Cloudflare, Inc. (Turnstile) | USA | Bot-prevention verification (if configured) | IP address, browser data |
We do not sell personal data, and we do not provide it to third parties beyond this processing, except where a lawful request (such as from law enforcement) requires it.
When you preview YouTube or Vimeo videos in the embed tool, those players load and their own cookie and privacy policies apply.
Operational alert webhooks (if configured) receive only minimal data with emails and names masked.
5. International transfers
To run the service, we transfer personal data abroad for entrusted processing and storage, disclosed here in accordance with Korea's Personal Information Protection Act (Article 28-8).
| Category | Recipient (contact) | Country | Data transferred | Retention |
|---|---|---|---|---|
| Hosting / DB | Vercel Inc. (vercel.com), Neon Inc. (neon.tech) | USA | Stored and transmitted account, content, and usage data | Until account deletion or the end of the contract |
| Build processing | Fly.io, Inc. (fly.io) | Japan (Tokyo region; US company) | Build prompts, generated output, member identifier | As long as needed to process the build |
| AI generation | Anthropic, PBC (anthropic.com) · Google LLC (google.com) · ElevenLabs (elevenlabs.io) · OpenAI, L.L.C. (openai.com, when enabled) · Amazon Web Services (aws.amazon.com, failover) | USA | Prompts, content, and attachments submitted to AI features | As long as needed to generate output (per provider policy) |
| Payments | PayPal Holdings, Inc. and affiliates (paypal.com) | USA and others | Payment amount, currency, transaction identifiers | Statutory transaction-record period |
| Messaging | Resend, Inc. (resend.com) · Twilio Inc. (twilio.com) | USA | Email address, phone number, message content | As long as needed to deliver |
| Security checks | Intuition Machines (hcaptcha.com) · Cloudflare (cloudflare.com) | USA | IP address, browser data | As long as needed to verify |
| Statistics (with consent) | Google LLC (policies.google.com/privacy) | USA | Usage statistics, device data | Google Analytics retention setting |
Timing and method: transferred continuously over encrypted network connections (HTTPS/TLS) as you use the service.
Refusal and consequences: you may refuse these transfers by contacting support@vibecampus.app. Because they are essential infrastructure, refusing may limit your use of the service. Refusing the statistics transfer (GA4) never limits your use in any way.
Safeguards: encryption in transit end to end, data processing agreements (DPAs) with processors including standard contractual clauses, and the other safeguards required by law.
6. Cookies and similar technologies
Cookies we set ourselves are listed below. We use no advertising cookies.
| Name | Type | Purpose | Lifetime |
|---|---|---|---|
| vc_session | Essential (HTTP-only) | Keeping you signed in | 30 days |
| vc_oauth | Essential (HTTP-only) | Anti-forgery state during social login | 10 minutes |
| vc_ghoauth · vc_sboauth | Essential (HTTP-only) | External connection (GitHub/Supabase) auth state | 10 minutes |
| vc_vcoauth | Essential (HTTP-only) | External connection (Vercel) auth state | 30 minutes |
| NEXT_LOCALE | Functional | Remembering your language choice | Browser session |
| _ga · _ga_* (Google) | Statistics (set only with consent) | Visit and usage statistics | Per Google policy (up to about 2 years) |
Statistics consent: choose in the banner on your first visit. Google Analytics 4 loads only if you agree (with IP anonymization). Declining never limits the service, and you can change your choice anytime via “Cookie settings” in the page footer.
Third-party cookies: PayPal on payment screens, hCaptcha and Cloudflare Turnstile on security checks (if configured), and YouTube/Vimeo players in embed previews may set their own cookies under their own policies.
Browser storage (localStorage etc.): your cookie choice (vc-consent), display settings such as theme and sound, local copies of studio and support conversations, funding campaign drafts, and dismissed-banner flags are stored in your browser, not on our servers. A service-worker app cache is used for offline support. You can clear all of it with your browser's data-clearing tools.
7. Your rights and how to exercise them
You may at any time request access, correction, deletion, restriction of processing, and withdrawal of consent. Directly in account settings you can: edit your profile and contact details, withdraw marketing consent (effective immediately), export your data (account, transactions, projects, posts as a JSON download), and delete your account (processed immediately).
For anything else (permanent erasure of retained deleted content, restriction requests, etc.), contact support@vibecampus.app. After verifying it is you (minimal checks such as confirming your account email), we act without undue delay within the periods set by law. You may also act through a legal representative or an authorized agent.
Exercising your rights never degrades your service. For complaints to supervisory authorities, see Section 10.
8. Security measures
We apply the following safeguards, all actually implemented:
• Passwords and secondary PINs are stored only as salted one-way hashes (scrypt), never in plain text. Sessions use HTTP-only, Secure, SameSite cookies, with remote session invalidation.
• All traffic is encrypted with HTTPS/TLS, with security headers (CSP, HSTS, X-Frame-Options) and sandboxed isolation of previewed content.
• Brute-force protection (login attempt limits and progressive delay), an optional secondary password (security PIN), and automated-attack checks (hCaptcha and similar).
• External service keys you register (BYO keys) are encrypted with AES-256-GCM; you can delete them in settings at any time and they are deleted on account closure. External connection keys (such as Supabase) are additionally destroyed automatically after 180 days of non-use.
• Least-privilege access; the source of for-sale builds is viewable/downloadable only by the owner and legitimate buyers; unauthorized scraping is blocked.
• The database runs on a managed cloud service whose backup and recovery mechanisms apply; content hashes are used to detect tampering.
No system is perfectly secure, so please use a strong, unique password (and the security PIN). If a breach occurs, we notify and report without delay as required by applicable law.
9. Children
VibeCampus is not directed at children under 14 (under 13 for US residents), and we do not intend to collect children's data. We do not currently collect dates of birth; signup requires confirming you are 14 or older by accepting the Terms.
If we learn that a child's data was collected without the required guardian consent, we delete it without delay. Parents and guardians: please contact support@vibecampus.app.
10. Privacy officer and remedies
Privacy officer: HUHJUNMIN (CEO) · contact: support@vibecampus.app. You may direct any privacy question, complaint, or remedy request there, and we will respond and act without undue delay.
For dispute mediation or counseling about privacy infringements, you can contact these Korean authorities:
• Personal Information Dispute Mediation Committee (privacy.go.kr / 1833-6972) · Privacy Infringement Report Center, KISA (privacy.kisa.or.kr / 118)
• Supreme Prosecutors' Office Cybercrime Department (spo.go.kr / 1301) · National Police Agency Cyber Bureau (ecrm.police.go.kr / 182)
Users outside Korea can also complain to their local supervisory authority (see the addenda in Sections 11 to 14).
11. EEA and UK addendum (GDPR)
This section applies to users in the European Economic Area and the United Kingdom. The controller is the company in Section 1. We have not appointed a DPO because we do not meet the mandatory designation criteria; direct all requests to the privacy officer in Section 10. No EU or UK representative is currently appointed.
Legal bases (GDPR Article 6): • Contract (Art. 6(1)(b)): providing your account, the service, AI features, and payments • Legitimate interests (Art. 6(1)(f)): security, fraud and abuse prevention, defending the service • Consent (Art. 6(1)(a)): marketing, statistics cookies • Legal obligation (Art. 6(1)(c)): transaction record-keeping, tax duties
You have the rights of access, rectification, erasure, restriction, data portability, and objection, and you may withdraw consent at any time (without affecting the lawfulness of processing before withdrawal). Exercise them as in Section 7.
We do not make decisions based solely on automated processing that produce legal effects on you or similarly significantly affect you.
Transfer safeguards: transfers from the EEA/UK to the Republic of Korea are covered by the European Commission's adequacy decision for Korea (2021) and the UK's adequacy regulations (2022). Transfers to processors in the USA and elsewhere are covered by data processing agreements incorporating Standard Contractual Clauses; some providers also hold EU-US Data Privacy Framework certification. See Sections 4 and 5 for the processor list.
Supervisory authorities: you may lodge a complaint with the authority of your member state (EEA list: edpb.europa.eu); in the UK, with the Information Commissioner's Office (ico.org.uk). If a breach poses a risk, we notify the supervisory authority within the GDPR deadline (72 hours as a rule) and take the required measures.
12. California addendum (CCPA/CPRA)
This section applies to California residents. We may fall below the CCPA's “business” thresholds (such as over $25 million annual gross revenue), but we honor the rights below for California residents regardless.
Categories of personal information collected in the last 12 months: • Identifiers (email, nickname, IP address) • Customer records (phone number; legal name and payout details for cash-outs) • Commercial information (purchase and transaction history) • Internet activity (usage statistics, only with consent) • Audio/visual information (content and profile images you upload) • Sensitive personal information limited to account login credentials, used only to provide the service. Sources, purposes, and recipients are as described in Sections 1 to 5.
We do not sell personal information, and we do not share it for cross-context behavioral advertising. A “Do Not Sell or Share My Personal Information” link is therefore not applicable. We do not sell or share the personal information of consumers we know to be under 16.
Rights: to know, access, correct, delete, limit use of sensitive personal information, and not to be discriminated against for exercising rights. Two ways to submit a request: (1) your account settings (data export, account deletion) or (2) email support@vibecampus.app. We verify requests via your account email; you may use an authorized agent.
13. Japan addendum (APPI)
This section applies to users in Japan. The purposes of use are published in Section 1 of this Policy.
Provision to third parties (processors) in foreign countries: your data is processed in the Republic of Korea (operations) and in the countries shown in the tables in Sections 4 and 5 (USA, Japan). Each processor is bound by contract and applies safeguards such as encryption. Information about those countries' data protection regimes is available in the survey materials published by Japan's Personal Information Protection Commission (ppc.go.jp).
Disclosure, correction, and suspension of use of retained personal data: request via account settings or email (no fee); we respond without undue delay. Security measures are as described in Section 8.
Contact: support@vibecampus.app. You may also consult Japan's Personal Information Protection Commission.
14. Users in China
We have no entity, servers, or dedicated representative in mainland China; the service is provided from the Republic of Korea. The Chinese-language interface is offered for convenience.
If you use the service from China, your personal data is transferred outside China (to Korea, the USA, and Japan) for processing. Recipients, items, purposes, and contacts are as shown in the tables in Sections 4 and 5. You can exercise access, correction, deletion, and account-deletion rights via account settings or email (Section 7).
If you do not agree to this offshore processing, you may stop using the service and request account deletion.
15. Effective date and change history
This revision takes effect on July 19, 2026.
• 2026-06-23: previous version in force
• 2026-07-19: full rewrite. Named processor and transfer tables; cookie and browser-storage inventory with consent-gated statistics; expanded generative-AI notice (ElevenLabs, OpenAI, and more); retention wording corrected to match actual operations; new EEA/UK, California, Japan, and China addenda
For material or unfavorable changes we give advance notice in the service. Previous versions are available on request at support@vibecampus.app.