Effective: August 10, 2026
Last updated: August 27, 2026
The short version
VXBE builds Buddy, a persistent AI companion that can remember context and help with work. That product cannot exist without storing the conversations, files, memory, and work state a person asks Buddy to keep. We disclose that plainly.
Our operating commitments are:
- We do not sell personal information or share it for targeted advertising.
- We do not use conversation content to train our own models.
- When VXBE pays for AI processing, we configure the route to deny provider training. OpenRouter's optional prompt logging is not enabled for ordinary inference, but an eligible underlying AI provider may still retain content temporarily for security, service operation, or legal compliance.
- Conversation text is not placed in ordinary product analytics, cost records, or service logs.
- Content review for product quality is off by default. A person can deliberately share feedback or turn on future quality-review sharing.
- Buddy's stored memory is context, not permission. A remembered fact cannot authorize an action.
- A narrow security-screening lane may copy a message flagged as a possible attempt to bypass Buddy's safeguards. A classifier alone does not punish or restrict an account.
- People can inspect, correct, forget, export, and delete account data through the controls that are available in the product. Some narrow records may be retained when required for security, fraud prevention, billing, disputes, or law.
- We keep a minimal, content-free record of the Terms version an account accepted so we can prove the agreement without storing extra device or conversation data.
This policy covers vxbe.space, vibecodr.space, the VXBE desktop application, Buddy, the private-preview waitlist, and related support and business communications.
1. Who we are
VXBE is a trade name used by Logan Braden Hartsell, a sole proprietor in Colorado, United States. In this policy, “VXBE,” “we,” and “us” refer to that business.
Privacy questions and requests can be sent to privacy@vxbe.space.
2. Who may use Buddy
Buddy is for people who are at least 18 years old and who use the service from the United States. We do not knowingly offer Buddy to children or collect their information. If you believe a child has provided information, contact us so we can remove it.
3. Information we process
3.1 Account and membership information
We process the information needed to create and secure an account, such as an email address, authentication identifiers, account status, membership tier, and sign-in security records. Clerk provides account authentication. Stripe processes payment details and provides VXBE with billing status, purchase identifiers, and the limited records needed to provide and reconcile paid service. VXBE does not receive full payment-card numbers.
When an account agrees to the Terms, VXBE records the Terms version and effective date, a cryptographic digest identifying the exact Terms document, the server-recorded acceptance time, the product surface where acceptance occurred, and the application release when available. This record does not include the conversation, the words a person typed, an IP address, or a user-agent string. It is used to administer the agreement, resolve disputes, and determine whether renewed acceptance is required after a material change.
3.2 Conversations, files, and work
We store messages to Buddy, Buddy's responses, attachments, saved files, action and tool results, connected-app results, schedules, activity, and related state so Buddy can answer, continue work, recover from interruptions, and show what happened.
Files and media may be processed into useful derivatives such as extracted document text, image descriptions, audio transcripts, video captions, page references, and searchable representations. Temporary media frames or audio segments may be created during processing and discarded after the durable result is produced.
Do not paste passwords, API keys, authentication codes, or other secrets into ordinary chat. When Buddy offers a dedicated secret-entry flow, that flow has separate handling and limited use.
3.3 Buddy memory and context
Buddy may derive and store relationship context from interactions, including preferences, standing instructions, ongoing items, corrections, important experiences, source references, and tentative patterns. Buddy may use that information across conversations to provide continuity.
The memory system distinguishes a direct fact from an inference, keeps source and revision information, and can withhold uncertain or sensitive information from ordinary retrieval. People can review, correct, or forget supported memory records. Memory and prior interactions remain context-only and cannot grant authority to send, purchase, delete, publish, connect, or take another action.
3.4 Voice
Speech input may be transcribed locally or by a service provider, depending on the available feature. When provider transcription is used, audio is sent for transcription and the resulting text may become part of the conversation. We disclose the active behavior in the product before relying on it.
3.5 Connected apps and computer-like work
If a person connects an outside service, Composio or another disclosed connection provider may store and refresh that connection and process the information needed for requested actions. The outside service also processes data under its own terms and privacy policy.
For work that needs a browser or computer-like workspace, selected infrastructure providers may receive the files, commands, page content, and results needed to do that work. VXBE limits the route to the requested work, but those providers operate their own systems.
Some no-auth capabilities are provided by isolated software packages. A networked package receives only the specific call arguments and admitted files needed for the requested work. It can contact only exact public HTTP or HTTPS hostnames that VXBE has reviewed for that exact package revision, on ports 80 or 443, through a short-lived relay. Packages do not receive account credentials, the conversation, memory, connected-app state, or an unrestricted internet connection. Cloudflare and E2B may process the proxied request bytes, destination hostname, network metadata, and isolated workspace metadata needed to run and secure that work. The destination service receives the request under its own terms and privacy policy.
3.6 Website, waitlist, and correspondence
Cloudflare processes ordinary request information needed to serve and protect the website, including IP address, requested route, browser information, timestamp, and security signals. Clerk stores private-preview waitlist email and invitation state. VXBE does not copy waitlist-only state into Buddy's product database.
The public website uses PostHog measurement for page views, page leaves, masked link and button interactions, closed public actions such as selecting Request access, pointer and scroll heatmaps, rage clicks, dead clicks, Core Web Vitals and their performance attribution, and bounded browser errors. Records can include a pseudonymous browser identifier, page path, referring origin, event time, browser and device class, approximate region, viewport, masked element structure, interaction position, performance measurements, and bounded exception diagnostics. VXBE strips query strings and fragments, removes nested resource URLs, element targets, and fixed-control heatmap coordinates, masks element text and attributes, and keeps person profiles and website session replay disabled.
Repeat-visit measurement is on by default. PostHog stores a random pseudonymous identifier and related session state in a first-party cookie and local storage on the current public website host for up to 365 days. VXBE keeps this website identity separate from Vxbe accounts, Buddy conversations, desktop telemetry, private invitation pages, and the Studio authoring surface.
Every measured public page provides a Website analytics control. A visitor can switch to cookieless measurement, which clears the saved analytics identity and keeps one local preference so the choice survives future visits. In cookieless mode, PostHog derives a daily pseudonymous visitor value from the project, daily salt, IP address, user agent, and hostname, then strips the IP address before storing the event. The value changes across days. The website also respects a browser's Do Not Track signal and uses cookieless measurement when that signal is active.
If someone emails or otherwise contacts us, we receive the address, message, attachments, and correspondence history they choose to send.
3.7 Buddy-made public sites
When a person asks Buddy to publish a saved browser experience, VXBE copies the prepared HTML and its title into public hosting at vibecodr.space. Anyone who has the stable link can open it. VXBE does not list these creations on the homepage or provide public search for them.
A new publication is normally available for 72 hours. The person can ask Buddy to keep up to 10 sites available while the account has active Pro access. A kept-live site remains public until the person releases it, the account returns to Free, or the account is deleted. Deleting the original saved file does not immediately remove a public copy that is still inside its stated lifecycle.
Each site can store up to 1 MiB of progress and preferences in the visitor's own browser. That browser-local information is separated by the site's stable identifier and is not sent back to VXBE by the storage bridge. Clearing browser storage removes it from that browser. Expiration, release, replacement, or account deletion closes the hosted site but cannot clear copies already stored under a visitor's browser controls.
A Buddy-made site can request public HTTPS data, images, media, styles, and fonts. Those requests come from an isolated browser origin and the destination receives ordinary request information under its own privacy terms. Cloudflare processes the public site bytes and ordinary request information needed to host, secure, and deliver the page.
3.8 Anonymous desktop telemetry
The desktop application sends anonymous, content-free product telemetry to PostHog so VXBE can see whether features work and where failures happen. Records cover speech feature outcomes, API failure codes, and app exception diagnostics, along with the app release version. Each app launch uses a random identifier that is not linked to an account, sign-in, device, or conversation. VXBE disables approximate location lookup and PostHog person profiles for this stream.
Exception diagnostics are limited to the exception class name, a short closed failure code, and compiled code locations such as a function name, source file name, and line number. The app never sends the error message itself, file contents, paths to personal files, or anything a person typed. Telemetry is one-directional: it measures the product and never changes what Buddy does.
4. How we use information
We use information to:
- provide conversations, memory, files, connected-app actions, schedules, and ongoing work;
- authenticate accounts and provide membership and billing;
- personalize Buddy and preserve continuity;
- process user-requested actions and return results;
- keep the service reliable, secure, and within operating and spending limits;
- measure content-free product flow, feature use, outcomes, latency, failures, provider usage, and cost;
- respond to support, feedback, privacy, and security requests;
- investigate abuse, fraud, credential compromise, destructive loops, or attacks on the service;
- enforce our Terms and Acceptable Use Policy;
- comply with law and resolve disputes; and
- communicate about the private preview, service, or material policy changes.
5. AI processing
Buddy sends content to AI services when processing is needed to answer, transcribe, describe media, create searchable representations, rank relevant context, form memory, evaluate turn quality, or perform requested work.
VXBE does not train its own models on conversation content. For VXBE-funded inference, requests travel through Cloudflare AI Gateway and the OpenRouter route is configured to deny provider training or data collection for training. OpenRouter says it does not store prompts or responses unless optional prompt logging or use-of-inputs controls are enabled; VXBE does not enable those controls for ordinary inference. This is not the same as zero retention by every eligible underlying AI provider. An underlying provider may retain request or response content temporarily for abuse prevention, service operation, or legal obligations under its terms.
If a person chooses a connected ChatGPT subscription or another user-funded AI connection, that provider's account terms and data controls apply to that route. VXBE still sends the request through its protected inference boundary when the product supports that connection.
AI systems can be wrong. They may generate inaccurate or incomplete information, and they may process content in ways that are difficult to predict. People should independently review consequential medical, legal, financial, employment, safety, or similar decisions.
6. Measurement and tracing without conversation text
VXBE uses closed, content-free records to operate the business. These records may include a pseudonymous or internal account or session reference, feature or capability name, event type, outcome, duration, bounded failure code, provider, model or route category, token or usage quantity, estimated or exact cost, device class, application version, and coarse request metadata.
Ordinary product analytics, cost records, usage ledgers, and service logs must not contain message text, prompts, memory text, file contents, tool arguments or results, credentials, email recipients, personal file names or paths, browser page content, commands, or arbitrary error text. The anonymous desktop exception diagnostics described in section 3.8 are limited to an exception class name, a closed failure code, and compiled code locations such as a function name, source file name, and line number. Technical platform logs can include IP address, user agent, requested route, timestamps, request identifiers, status, and other infrastructure metadata. These records can still be personal information even when they contain no conversation words.
VXBE may use these content-free records to understand whether people complete important flows, where failures occur, which capabilities are useful, how long work takes, whether a release regressed, and what the service costs to operate.
Your Buddy Logs
Buddy Logs are separate from the content-free measurement described above. After signing in, a person can use the private Buddy Logs page to inspect and download the technical history stored for their own account. It can include their prompts sent to an AI service, Buddy's returned text and reasoning that the service returned to VXBE, model details, tool calls and results, errors, successes, retries, recoveries, and account, session, turn, and event references needed to connect those facts.
Buddy Logs do not include system prompts, developer prompts, hidden security-policy text, secret values such as passwords or tokens, another person's content, or private reasoning an AI provider did not return to VXBE. If the provider did not return reasoning, VXBE records that it was not returned rather than attempting to recreate it. Buddy Logs remain private account product data. They are not sent to public website analytics, ordinary service logs, support systems, or model context merely because the account can view them.
Optional content review
Optional AI-content review is off by default. If a person turns it on, new AI requests and responses use VXBE's standard content-review Gateway and may be retained there for VXBE's restricted quality and debugging review to fix problems and improve Vxbe and Buddy. If a person leaves it off, new AI requests and responses use VXBE's separate no-content-export Gateway, where VXBE does not store or retrieve their request or response payloads.
A person may also deliberately share a conversation or Buddy report through feedback or support. The product explains what will be shared before a one-time feedback submission. VXBE keeps the shared package in its own feedback records and founder-support channel, and also sends that same consented package to PostHog Support so VXBE can work the report there. PostHog may additionally store a short excerpt of each shared message (currently the first 1,000 characters) in its native conversation analytics events for that Support ticket. This PostHog path is secondary to VXBE's own records and is listed on the Subprocessors page.
VXBE periodically deletes user-shared feedback after it has served its support and product-improvement purpose, including the PostHog Support ticket and those native conversation analytics copies when cleanup covers them. A longer period may be needed to finish requested support, investigate a reported security problem, meet a legal obligation, or preserve a dispute record. Turning off optional review stops new optional exports but does not instantly erase a copy already retained for these disclosed purposes.
7. Security and acceptable-use screening
VXBE may run automated classifiers and technical controls to identify service failures, prompt-injection attempts, credential compromise, fraud, spam, destructive automation, or attempts to access another person's data. Morph, our current classification provider, may receive the user message or Buddy response being classified. That provider processing is separate from the restricted incident-review store described below.
Most quality signals, such as frustration, an incomplete thought, a looping response, or a possible reasoning leak, are stored only as content-free operational observations after classification. They are used to improve reliability and are not security accusations. VXBE does not copy the classified words into those quality-signal records.
When the prompt-bypass classifier flags a user message as a possible attempt to bypass Buddy's safeguards, VXBE may copy that exact user message into a restricted incident-review store. Buddy's response and the surrounding conversation are not copied into that incident record. A human decision is required before a classifier-only flag becomes a confirmed incident. Cleared or inconclusive incident content is deleted after review, and its content-free ledger entry ages out on a rolling 90-day schedule.
VXBE does not suspend or terminate an account solely because a content classifier produced a label. We may apply automated technical containment based on direct operational evidence, such as invalid authentication, excessive traffic, confirmed credential compromise, repeated fenced-effect failures, malware delivery, or an active attack. Containment can include rate limiting, stopping an action, revoking a compromised session, or temporarily isolating a capability while the event is investigated.
Confirmed incident evidence may be retained while reasonably needed to protect users and the service, enforce restrictions, resolve a dispute, or comply with law. Access to incident content is restricted and reason-audited.
8. When people at VXBE may read content
VXBE does not browse private conversations as a normal product practice. Content may be accessed only when:
- a person deliberately shares it for feedback or support;
- optional content review is enabled for new activity, in which case VXBE may read the retained standard-Gateway request or response needed to fix problems and improve Vxbe and Buddy;
- the narrow security process in section 7 creates an incident record;
- access is necessary to investigate a user-reported failure and the person has shared or authorized the relevant material;
- access is needed to comply with a valid legal obligation; or
- access is needed to recover from or contain an active security incident where less intrusive evidence is not sufficient.
Access should be limited to the smallest useful scope and recorded when the system provides an access-audit path. As VXBE hires, access will be limited by job function rather than by a promise that only one named person can ever operate the service.
9. Providers and disclosures
VXBE uses service providers to operate the product. The current list and each provider's purpose are maintained on the Subprocessors page. Categories include hosting and security, databases and storage, identity, payments, AI inference and media processing, connected apps, computer-like work, analytics, email, and messaging and communication delivery.
We may disclose information when reasonably necessary to:
- comply with law, court order, or valid legal process;
- protect a person, VXBE, or the public from serious harm;
- investigate fraud, abuse, or a security incident; or
- complete a merger, financing, acquisition, reorganization, or sale of assets.
If control of VXBE changes, this policy continues to apply until the new operator gives legally required notice of a material change.
VXBE does not sell personal information and does not share it for cross-context behavioral advertising.
10. Retention
Retention depends on purpose:
| Information | General retention approach |
|---|---|
| Account, conversations, memory, files, and work state | While the account is active and until the person deletes the item or account, subject to narrow exceptions below |
| Account-owned Buddy Logs | While the account is active, including after Pro access ends; deleted with the account |
| Buddy-made public site copy and lifecycle metadata | Public for 72 hours after successful publication or resend, or while the person keeps it live under active Pro access; unavailable copies are removed through hourly cleanup, while stable nonpublic metadata can remain with the account so redeployment returns to the same URL |
| Transient message delivery and retry queues | Until processing succeeds, or no more than four days after the final failed processing attempt |
| Temporary secret-entry material | The short, single-use period shown in the product |
| Waitlist-only email | Until removal, unsubscribe, invitation-state closure, or the end of the preview |
| User-shared feedback or support package (including PostHog Support tickets and native conversation analytics copies) | Deleted during periodic feedback cleanup after it has served its purpose, unless support, security, fraud, dispute, or law requires longer |
| Opted-in AI-content review Gateway request and response payloads | According to the configured Gateway and provider retention schedule; turning the setting off stops new payload capture |
| Cleared or inconclusive security content | Deleted on review; the content-free ledger ages out after 90 days |
| Confirmed security, fraud, and restriction evidence | While reasonably needed for protection, enforcement, disputes, or law, with periodic review |
| Product analytics and pseudonymous event records | According to the configured analytics retention needed for product and business measurement |
| Service and infrastructure logs | A limited operational period based on the system and security purpose |
| Billing, transaction, tax, and entitlement records | As needed for accounting, disputes, fraud prevention, and legal obligations |
| Terms acceptance evidence | Retained as a content-free contract record while reasonably needed to administer or prove the agreement, resolve disputes, or comply with law, including after account deletion |
| Backups | Until overwritten through the backup cycle or isolated for a security or legal reason |
We do not promise instant removal from every backup. Deleted information is not restored to active service merely because it remains in an expiring backup.
Transient delivery and retry queues exist only to finish or recover a message the person asked VXBE to process. They are not analytics, model training data, or a second conversation archive. Cloudflare automatically deletes a queued message when its retention period ends. Because these queues do not support deleting one person's message by account, account deletion relies on this fixed short expiry for any message already in flight.
11. Controls and privacy rights
Depending on the feature and account state, people can:
- inspect, correct, or forget supported Buddy memory;
- delete conversations, files, schedules, connected apps, or an account;
- release a kept-live Buddy-made site or delete the account to close its public route;
- export supported account data;
- inspect and download account-owned Buddy Logs from a phone or computer;
- turn optional content review on or off;
- disconnect connected apps;
- unsubscribe from marketing; and
- ask VXBE to access, correct, delete, restrict, or provide a copy of personal information.
Send a request to privacy@vxbe.space. We may need to verify identity before acting. We aim to respond within 45 days and will explain if more time is allowed and needed. If we deny a request, the response will explain why and how to appeal by replying.
Deletion may exclude records that must be retained for transaction accounting, chargebacks, contract acceptance, security, fraud prevention, legal obligations, litigation holds, or the minimal tombstone needed to prevent a deleted or restricted account from being silently recreated. We will limit those records to the relevant purpose.
Some state privacy laws apply only above business-size thresholds that VXBE may not meet. We nevertheless offer the controls above as an operating commitment. We do not discriminate against someone for making a privacy request.
12. Security
VXBE uses measures intended to protect information, including encrypted connections, provider encryption at rest, scoped credentials, account and session ownership checks, secret sanitation, bounded execution, access controls, and purpose-specific audit records. No service can promise perfect security.
Report a suspected vulnerability or account compromise to privacy@vxbe.space with “Security” in the subject. Do not include another person's private data in the report.
13. Cookies and tracking
The public website uses first-party PostHog storage for repeat-visit measurement as described in section 3.6. A random pseudonymous identifier and related session state can remain for up to 365 days. The fixed Website analytics control switches the browser to cookieless measurement and clears that saved analytics identity while retaining one local preference. Do Not Track also selects cookieless measurement.
VXBE uses this storage for its own public-site product and business measurement. Advertising pixels, cross-site behavioral profiles, account-linked website profiles, and marketing-site session replay stay outside this lane. Authentication, payment, and security surfaces may use separate storage needed to sign in, protect a session, remember settings, or complete a purchase. VXBE will request consent before nonessential storage when law requires it.
14. International access
VXBE operates from the United States and currently offers Buddy to United States users. Providers may process information in the United States and other locations where they operate. Visitors who access the website from elsewhere understand that information may be transferred to the United States.
15. Changes
VXBE will update the “Last updated” date when this policy changes. For a material change that adds a new data category, new purpose, new class of recipient, or meaningfully narrows a commitment in the short version, we will provide notice in the product, on the website, or by email before the change takes effect when reasonably possible. We will request consent when law requires it.
16. Contact
Email privacy@vxbe.space. If a postal address is required for a formal request, ask by email and we will provide the appropriate current address.