Privacy Policy.
vibedraft publishes to social accounts you connect. To do that it has to hold some of your data. This page says what, why, where it goes, and how to get it removed. Effective 7 September 2026. The operator is Ricky Miskin, trading as vibedraft, at vibedraft.app.
What we collect, and why.
Your sign-in. You sign in with Google. We store the email address, name and avatar Google shares so we know who you are. There is no password.
Connected accounts.When you connect an X, Instagram or TikTok account we store the access and refresh tokens that platform issues, encrypted at rest, plus the account’s id, handle, display name and avatar. Tokens are used only to publish what you asked to publish and to read the metrics of those posts. Disconnecting an account deletes its tokens.
Your content. Drafts, scheduled posts, uploaded images and videos, the posts you published through vibedraft, and their metrics (impressions, likes, replies, views and the like) as the platforms report them.
Your voice and memory. A voice profile derived from posts you already published, and an account memory of what you tell the assistant about yourself and your business, so drafts sound like you and advice is not generic. You can read, correct and forget entries at any time.
Public data about others. Handles you choose to track and public posts vibedraft reads to find things worth replying to. We do not collect private data about anyone.
Billing. Your plan, credit balance and a record of what each credit was spent on. Card details go to Stripe and never touch our servers.
Usage. Which features are used and errors that occur, so we can fix them. No advertising identifiers, no cross-site tracking.
TikTok, Instagram and X specifically.
For TikTok we request only what publishing needs: your basic profile and username (to show which account is connected), the list of videos you published through vibedraft (to report their performance back to you), and permission to publish on your behalf. Every TikTok post goes through TikTok’s Content Posting API after you have chosen its privacy level and seen the preview; vibedraft never posts without that step. You can revoke vibedraft at any time under TikTok’s Settings, Security and permissions, Manage app permissions, and we will stop at once.
The same holds for Instagram, through Meta’s Instagram API, and for X, through the X API. We only ever read your own posts and their metrics, and the public posts of accounts you asked vibedraft to follow. We never read direct messages.
Who processes it for us.
We do not sell or rent your data, and we do not train models on it. It is processed by these providers, each under its own agreement with us, and only for the purpose named:
How long we keep it.
For as long as your account exists. Platform tokens are deleted the moment you disconnect an account. When you ask us to delete your account, everything above is deleted within 30 days, except records we must keep for tax and fraud purposes (receipts, not content), which are kept only as long as the law requires.
Your rights.
You can see most of what vibedraft holds about you from inside the app, correct or forget account memory yourself, disconnect any platform yourself, and ask us for a copy or a deletion of the rest. We answer within 30 days. If you are in the EU, UK or a jurisdiction with similar rights, they apply in full; nothing here narrows them.
Cookies and security.
vibedraft sets a session cookie so you stay signed in, and a PostHog cookie for product analytics. There are no advertising cookies. All traffic is over HTTPS, and platform tokens are encrypted at rest with a key held outside the database.
Children, changes and contact.
vibedraft is not for anyone under 18 and we do not knowingly hold data about children. When this policy changes materially, the effective date changes and the change is announced on the blog first. Requests and questions go to @rcmisk on X, or to the support address on any vibedraft receipt. The terms of service cover the rest.