Effective date: 20 July 2026
Last updated: 20 July 2026
Website: https://vibeark.co.in
This Privacy Policy explains how Vibeark ("Vibeark", "we", "us") collects, uses, shares, and protects information when you use the Vibeark platform (the "Service"). It should be read with our Terms of Use and Cookie & Local Storage Policy.
We act as a Data Fiduciary under the Digital Personal Data Protection Act, 2023 ("DPDP Act") and follow applicable Indian law, including the Information Technology Act, 2000 and its rules. Vibeark is for users 18 and older; we do not knowingly process the personal data of children.
This summary is for convenience only and does not replace the full policy below.
The Data Fiduciary responsible for your personal data is Vibeark, sole proprietorship operated from India. For privacy questions, contact vibearkin@gmail.com or our Grievance Officer (Section 10).
We collect the following categories of information.
We do not ask for government IDs, financial account details (unless and until paid features are introduced — see the Refund & Subscription Policy), or sensitive categories of data. Please do not share sensitive personal information in chats.
We use information to:
1. Provide and operate the Service — create your account, authenticate you via email OTP, deliver chats, and match you with a real user or the AI Companion.
2. Maintain safety and integrity — detect and prevent abuse, fraud, spam, and prohibited activity; review reports; and enforce our Terms of Use and policies.
3. Improve the Service — understand usage and fix problems. AI Companion conversations may be used to improve the Service only where disclosed (see the AI Chat Companion Policy).
4. Communicate with you — send OTPs, service notices, and responses to your requests.
5. Comply with law — respond to lawful requests, preserve evidence, and meet legal obligations. See Section 6.
Legal basis (DPDP Act): we process your personal data based on your consent (given when you register and use the Service) and, where applicable, for legitimate uses permitted by law, such as complying with legal obligations and responding to safety or security threats.
When you chat with the AI Companion, your messages are processed to generate replies. This may involve our AI provider. Conversations may be logged only for service improvement where disclosed, and to maintain safety. For full details — including that the AI is clearly labelled, may be inaccurate, and is not professional advice — see the AI Chat Companion Policy.
Our AI provider: the AI Companion is powered by Google Gemini. Your messages to the AI Companion are sent to Google to generate replies, and are handled under Google's applicable API terms. Depending on the API tier in use, Google may retain this content and use it to improve its own services, and we have not configured any provider-side guarantee to the contrary. Please treat AI Companion chats as not private and do not share sensitive personal or financial information with the AI Companion. See the AI Chat Companion Policy.
We do not sell your personal data. We share it only as follows:
We use trusted third parties that process data on our behalf under contract:
We do not currently use third-party analytics providers.
Your username and any profile details you choose to make visible are shown to users you chat with. Anything you send in a chat is shared with the person (or AI) you are chatting with. Choose carefully what you reveal.
We may disclose information where we believe in good faith it is necessary to: comply with law, legal process, or a lawful government request; enforce our Agreement; detect, prevent, or address fraud, abuse, or security issues; or protect the rights, property, or safety of users, the public, or Vibeark. See Section 6 and the Law Enforcement Request Policy.
If Vibeark is involved in a merger, acquisition, or sale of assets, your information may be transferred, subject to this Policy.
6.1 We may preserve and disclose information in response to valid legal requests (such as court orders or requests from authorised agencies), consistent with the Law Enforcement Request Policy.
6.2 In an emergency involving a risk of death or serious physical harm, we may disclose information to the appropriate authorities where permitted by law, without prior notice to you.
6.3 We may preserve evidence (including messages, logs, and account records) where required by law or reasonably necessary to investigate abuse or protect our legal rights.
Some of our service providers may store or process data outside India. Where this happens, we take steps to ensure the data is handled consistently with this Policy and applicable law, including any restrictions the Government of India may notify under the DPDP Act. Our providers (Supabase, Render, Cloudflare, Brevo, and Google) may store or process data in data centres located in India and/or other countries.
We keep personal data only as long as needed for the purposes in this Policy, then delete or anonymise it, unless a longer period is required by law.
| Data type | Retention |
|---|---|
| Account & profile data | While your account is active; deleted or anonymised after account deletion, subject to legal exceptions |
| Messages / chat content | Kept while your account is active; deleted or anonymised after you delete your account, unless we must keep it for legal or safety reasons |
| Queue / matchmaking data | Transient — used only while matching you to a chat partner and not stored long-term |
| Server & access logs (incl. IP) | Up to 90 days (longer only if needed for security or legal reasons) |
| Abuse reports & moderation records | Up to 24 months |
| Backups | up to 30 days |
Deleted-account handling. When you delete your account (see the Account Deletion Policy), we delete or anonymise your personal data within a reasonable period, except data we must retain to: comply with law, resolve disputes, prevent fraud or abuse, or preserve evidence. Residual copies may persist in backups until they are rotated out within up to 30 days.
Subject to applicable law (including the DPDP Act), you have the right to:
To exercise these rights, contact vibearkin@gmail.com. We may need to verify your identity (for example, via your registered email) before acting.
In line with the DPDP Act and the IT Rules, 2021:
Grievance Officer: Vibeark Grievance Team
Email: vibearkin@gmail.com
We will acknowledge complaints within 24 hours and aim to resolve them within 15 days (or sooner where the law requires).
11.1 We use reasonable technical and organisational measures to protect personal data, including:
We list only measures we have actually deployed. No list of safeguards makes a service risk-free — see 11.2.
11.2 No perfect security. No method of transmission or storage is completely secure. We cannot guarantee absolute security, and you use the Service at your own risk.
11.3 Your responsibility. Keep access to your email secure, since email OTP controls access to your account. See Section 2 of the Terms of Use.
11.4 Data breaches. If a personal data breach occurs, we will act in accordance with the DPDP Act and applicable law, including notifying the Data Protection Board and affected users where required.
11.5 Responsible disclosure. If you discover a security vulnerability, please report it to vibearkin@gmail.com. Do not exploit it or access others' data. See the Safety Policy.
We use cookies, local storage, and session storage to keep you signed in and to operate the Service. See the Cookie & Local Storage Policy.
Vibeark is for adults 18 and older. We do not knowingly collect personal data from anyone under 18. If we learn that we have, we will delete the account and data. If you believe a minor is using the Service, contact vibearkin@gmail.com.
We may update this Policy from time to time. If we make material changes, we will take reasonable steps to notify you (for example, an in-app or on-site notice). The "Last updated" date shows the latest revision. Continued use after changes means you accept the updated Policy.