Legal · Closed-beta draft

Privacy Policy

Last updated 2026-05-24 · Effective on public-beta launch · Adults only (18+)

What we collect

We collect the minimum data required to operate the service. That breaks down into a few categories:

Account data

  • Email address (required) and a hashed password or single-sign-on identifier.
  • Display name or pseudonym, if you provide one. We do not require real names.
  • Date-of-birth attestation at signup; on public launch this becomes a verified age check via a third-party provider (see §4).

Scene data

  • Hard limits, soft limits, safe word(s). Required to operate any scene safely.
  • Scene transcripts — the messages exchanged during a scene, plus voice transcripts if voice mode is enabled.
  • Custom protocols you upload (PDF, text).
  • Aftercare records — hydration check-ins, mood notes, anything else the aftercare feature collects with your explicit opt-in.
  • Persona selections, settings, and preferences.

Billing data

  • Subscription tier, billing interval, invoices. We do not store your full card number — that lives only with our payment processor.

Technical telemetry

  • IP address (used for rate-limiting and geographic routing), browser/device type, session timestamps, error reports, and aggregated usage counters.

How we use it

We use the data we collect to:

  • operate the service — generate persona responses, run scenes, keep your preferences between sessions, deliver aftercare;
  • enforce safe words and the twelve-hour lockout (see Terms §5);
  • process payments and prevent fraud;
  • respond to support, abuse reports, and security incidents;
  • investigate violations of our Trust & Safety policy;
  • comply with applicable law and respond to valid legal process.

We do not use your scene content to train shared models. We do not target advertising at you on this site, and we do not allow third-party advertising trackers on the site at all.

Scene content is sensitive personal information

We treat scene transcripts, voice recordings, custom protocols, and aftercare records as sensitive personal information regardless of whether the law of your jurisdiction technically classifies them that way. In practical terms that means:

  • Scene content is encrypted in transit and encrypted at rest with keys we control. Access is logged.
  • Scene content is not visible to support staff except as part of a specific abuse, security, or legal investigation, with internal access review.
  • Scene content is not shared with third parties for analytics, advertising, or training.
  • Scene content is excluded from any product telemetry stream. Telemetry sees that a scene happened, not what was in it.

Sharing and subprocessors

We do not sell your personal information. We share it only with the third parties we need to operate the service and where the sharing is necessary and proportionate. By category:

  • Inference subprocessor — the LLM and TTS/STT providers that generate persona responses. Scene transcripts pass through them at runtime and are not retained by them under our agreements. The active subprocessor list (specific provider names) will be published on this page before public launch.
  • Payment processor for subscription billing.
  • Transactional email provider for account verification, billing receipts, and aftercare emails you've enabled.
  • Cloud infrastructure — hosting, edge delivery, encrypted storage.
  • Age-verification provider at public launch.
  • Legal process — we disclose data when required by valid subpoena, court order, or equivalent legal demand. We push back on overbroad or improper requests.

Retention and deletion

Retention is the load-bearing privacy question for an adult service. Our defaults:

  • Scene transcripts: retained for 12 months from the end of the scene, then deleted. You can shorten this to 30 days, session-only, or delete on close in your settings, and you can delete individual scenes at any time.
  • Voice recordings: if voice mode is enabled, raw audio is retained for 72 hours for quality investigation and then deleted; the transcript follows the scene-transcript retention rule.
  • Custom protocols: retained while your account is active. Deleted within 30 days of account closure or upon explicit request.
  • Aftercare records: retained for 12 months by default; shortenable in settings.
  • Account metadata (email, display name, settings) retained while the account is active.
  • Billing records retained for the period required by applicable tax and financial-records law (typically 7 years), independent of account closure.
  • Telemetry retained 90 days at granular resolution, aggregated thereafter.

On account deletion, we erase everything we are not legally required to keep, within 30 days, and we confirm by email when the erasure is complete.

Your rights

Depending on where you live, you have some or all of these rights — and we honor them globally to the extent reasonably possible, not just where a specific law requires:

  • Access — request a copy of your data.
  • Portability — export your scene transcripts, custom protocols, and settings in a structured format.
  • Correction — fix anything that is wrong.
  • Deletion — erase your data, subject to the legal retention rules above.
  • Restriction / objection — limit how we process specific categories.
  • Withdrawal of consent — opt out of aftercare emails, telemetry, or any other optional processing.
  • Complain to your local data-protection authority. We would prefer you write to us first; if we can fix it, we will.

Account settings include self-service controls for most of these. For anything that isn't self-service, email privacy@vibedungeon.ai; we respond within 30 days (faster where the law requires it).

Cookies and tracking

This site uses no third-party analytics, no advertising pixels, and no cross-site behavioral cookies. There never will be on the product either. The only local state we set is a single localStorage entry, vd_cookie_consent, which records the choice you made in the consent banner so we do not show it to you again. It is stored on your device only, sent to no one, and does not expire.

We do measure aggregate traffic, but we do it entirely on the server. No analytics script runs in your browser, no beacon is loaded from a tracking domain, and no identifier is set on your device to recognize you across requests. The full shape of what we record is enumerated in the disclosure box at the top of this page.

The full granular consent surface — including the three currently-empty categories (analytics, advertising, functional) listed for completeness — is available via the Cookie preferences link in the footer of every page, or directly here. Changing your choice writes a fresh vd_cookie_consent entry and is effective immediately.

Security

We use TLS for all transport, modern at-rest encryption for stored data, separated key management for sensitive content categories, principle-of-least-privilege access controls, single-sign-on with hardware-key enforcement for staff access, and access logging that we review. We will publish a SOC 2 Type II report before sales of the Enterprise tier open.

If you find a security issue, report it to security@vibedungeon.ai. We don't run a bug bounty yet, but we do read every report, respond promptly, and credit researchers who want credit.

International data transfers

We are organized in the United States and our primary infrastructure is in the United States and the European Union. For users in the EEA, UK, or other jurisdictions with cross-border transfer rules, we rely on Standard Contractual Clauses (SCCs) with our subprocessors and offer a Data Processing Addendum on request. Specific transfer mechanisms will be enumerated here before public launch.

Children

Vibe Dungeon is strictly adults-only. We do not knowingly collect data from anyone under 18 (or the age of majority in their jurisdiction, whichever is higher). If we discover that an account belongs to a minor, we terminate the account and delete the data. If you believe a minor has created an account, tell us immediately at trust@vibedungeon.ai and we will act the same day.

Changes to this policy

We will tell you when this policy changes in a way that materially affects you — by email and by an announcement at the top of this page — at least 30 days before the change takes effect. The "Last updated" date is the single source of truth for which version is in force.

Contact and Data Protection Officer

For privacy questions or to exercise any of the rights above, write to privacy. For trust and safety reports, use the dedicated trust address. We will appoint a named DPO and EU/UK representative before public launch and list them here.

Privacy: privacy@vibedungeon.ai
Trust & safety: trust@vibedungeon.ai
Security: security@vibedungeon.ai
Data Protection Officer: to be appointed before public launch