1. Introduction and Scope
This Privacy Policy explains how SmartVibe AI ("SmartVibe", "we", "us", "our") collects, uses, discloses, transfers, retains and protects personal data in connection with smartvibe.dev and the SmartVibe platform (the "Services"), and describes the rights available to you.
It applies to: visitors to our website; individuals who register for and use the Services; Authorised Users on an organisational account; individuals who contact our support or sales teams; and recipients of our service communications. It does not apply to (a) personal data you process within applications you build using the Services, where you are the controller and we act on your behalf, (b) third-party services you connect to the Services, each of which has its own privacy policy, or (c) any website or product not operated by us.
1.1 Our role: controller and processor
We act in two distinct capacities, and it matters which applies:
-
We are the controller (or "data fiduciary" under India's DPDP Act) for personal data we process to operate our business — your account and identity data, billing data, support communications, security logs, product analytics and marketing data. Sections 4 to 11 and 12 to 16 of this policy describe that processing.
-
We are a processor (or "data processor") for personal data contained in your Customer Content — the files, databases, prompts and records you place in your Projects. Here you determine the purposes and means, we act on your instructions, and our Data Processing Addendum governs the processing. If your end users have questions about that data, they should contact you as the controller, and we will refer them to you.
Where a Workspace is administered by your employer or another organisation, that organisation is the controller of Account data within the Workspace, and its own privacy notice governs its handling of your information.
2. Who We Are and How to Contact Us
| Role | Details |
| Controller / Data Fiduciary | SmartVibe AI, India |
| Privacy contact | privacy@smartvibe.dev — for all privacy questions, rights requests and complaints |
| Data Protection Officer / Grievance Officer (India, DPDP Act s.13 & IT Rules 2021) | Contact via privacy@smartvibe.dev or grievance@smartvibe.dev. Current name and postal contact details are published at smartvibe.dev/legal/grievance. Requests are acknowledged within 24 hours and resolved within the statutory period. |
| EU representative (GDPR Art. 27) | Where required because we offer the Services to individuals in the EEA, our appointed representative is identified at smartvibe.dev/legal/eu-representative. Until an appointment is published, EEA individuals may contact privacy@smartvibe.dev directly. |
| UK representative (UK GDPR Art. 27) | Identified at smartvibe.dev/legal/uk-representative where required. |
| Security reports | security@smartvibe.dev |
You may contact us in English. We aim to acknowledge every privacy enquiry within five (5) business days.
3. Definitions
"Personal data" (also "personal information" or "personal data" under the DPDP Act) means information relating to an identified or identifiable individual. "Processing" means any operation performed on personal data. "Special category data" means data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data for identification, health data, or data concerning sex life or sexual orientation. "Data subject", "consumer" and "Data Principal" mean the individual to whom personal data relates under the GDPR, the CCPA/CPRA and the DPDP Act respectively. "Sub-processor" means a third party engaged by us to process personal data on our behalf. Other capitalised terms have the meanings given in the Terms of Service.
4. Personal Data We Collect
We collect the categories of data set out below. Not all categories apply to every individual; what we hold about you depends on how you use the Services.
4.1 Data you provide directly
| Category | Examples | Source |
| Account and identity data | Name or display name, email address, password hash, profile picture, organisation name, job role, country, timezone, language preference, avatar | You; identity provider |
| Authentication data | Session tokens, multi-factor authentication configuration and recovery codes, OAuth tokens and refresh tokens for connected services, SSO assertions, API key metadata | You; identity provider; Integration |
| Prompts and AI inputs | Text instructions, questions, uploaded images and screenshots, error messages, pasted code, schema definitions, file and repository context assembled to answer your prompt | You |
| Customer Content | Project source code, files, assets, configuration, environment variable names, database schema and, where you place it there, database contents; personal data of your own end users where you choose to include it | You |
| AI Output | Generated code, explanations, migrations, commit messages, tests, documentation and other output produced for you | Generated by the Services |
| Billing data | Billing name, billing address, tax identifier such as GSTIN, plan and subscription history, invoices, transaction identifiers, last four digits and card brand, currency. We do not receive or store full payment card numbers. | You; payment processor |
| Support and communications | Support tickets and email correspondence, chat transcripts, attachments, screenshots and screen recordings you send us, feedback, bug reports, survey responses, call notes | You |
| Marketing preferences | Subscription status for product updates and newsletters, consent records, event registrations, waitlist entries | You |
4.2 Data collected automatically
| Category | Examples | Purpose in brief |
| Device and connection data | IP address, approximate location derived from IP at city level, browser type and version, operating system, device type, screen resolution, language headers, user agent | Security, fraud prevention, compatibility, regional routing |
| Usage and product analytics | Pages and features viewed, clicks and navigation paths, session duration and frequency, feature adoption, onboarding progress, referring URL, search terms within the Services | Product improvement, diagnostics |
| AI and platform telemetry | Prompt and response token counts, model selected, latency, Credit consumption, tool-use steps, retries, acceptance or rejection of suggestions, error and refusal codes | Billing accuracy, reliability, abuse detection |
| Build and runtime logs | Sandbox build output, package installation logs, terminal command history, runtime and console errors, stack traces, Live Preview request logs | Debugging, support, abuse detection |
| Security logs | Authentication events, IP and user agent for sessions, permission changes, administrative actions, API key use, rate limit and abuse-control triggers | Security, incident investigation, audit |
| Cookies and similar technologies | Cookie identifiers, local storage entries, session identifiers, pixel and SDK identifiers. See the Cookie Policy. | Authentication, preferences, analytics |
4.3 Data from third parties
-
Identity providers — where you sign in with Google or another provider, we receive the identifiers and profile fields you authorise (typically email address, name, profile picture and provider account ID). We never receive your password.
-
GitHub — where you connect GitHub, we receive your GitHub account identity, and, within the scopes you grant, repository metadata, branch and commit information and file contents for authorised repositories.
-
Supabase — where you connect Supabase, we receive project identifiers, configuration, schema metadata and the credentials you supply.
-
Payment processors — Stripe and Razorpay provide transaction outcomes, card metadata, fraud signals, chargeback notices and tax status.
-
Service providers — analytics, error monitoring, email delivery and support tooling return processed data about your interactions with the Services and our messages.
-
Publicly available sources — for business prospects only, we may use publicly available professional information, such as a company website or a professional network profile, to contact organisations about Enterprise plans. You may object at any time.
4.4 Data we ask you not to provide
The Services are not designed for special category data, payment card data, health information, government identity numbers beyond billing needs, biometric data or children's data. Section 11.2 of the Terms of Service prohibits placing such data in the Services without a written agreement. We do not intentionally collect special category data, and if you place it in Customer Content you do so as controller and at your own risk.
5. How and Why We Use Personal Data, and Our Legal Bases
Where the GDPR or UK GDPR applies, we rely on the legal bases identified below. Where the DPDP Act applies, we rely on your consent or on a legitimate use permitted by that Act. Where the CCPA/CPRA applies, we use personal information only for the purposes disclosed at or before collection and compatible purposes.
| Purpose | What this involves | Legal basis (GDPR / UK GDPR) |
| Providing the Services | Creating and authenticating your Account, storing and serving Projects, provisioning Sandboxes, rendering Live Preview, running Integrations, delivering AI features | Performance of a contract (Art. 6(1)(b)); consent under DPDP Act s.6 where applicable |
| Delivering AI features | Transmitting your Prompt and assembled context to a model, returning AI Output, retaining a short-term record to maintain conversation state and support debugging | Performance of a contract (Art. 6(1)(b)) |
| Billing and administration | Charging fees, metering Credit consumption, issuing invoices, tax compliance, collecting overdue amounts, managing renewals and refunds | Contract (Art. 6(1)(b)); legal obligation (Art. 6(1)(c)) for tax and accounting records |
| Support | Responding to tickets, reproducing reported issues, and — only where necessary and where you request or authorise it — accessing your Project to diagnose a problem | Contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) |
| Security, fraud and abuse prevention | Detecting credential stuffing, bot traffic, resource abuse, crypto mining, phishing content, AUP violations; investigating incidents; maintaining audit logs | Legitimate interests in protecting the Services, our customers and third parties (Art. 6(1)(f)); legal obligation (Art. 6(1)(c)) |
| Reliability and improvement | Diagnosing errors, monitoring performance, capacity planning, measuring feature adoption, testing changes, using aggregated and de-identified metrics | Legitimate interests in operating and improving the Services (Art. 6(1)(f)) |
| Service communications | Sending transactional messages: security alerts, billing notices, quota warnings, incident notifications, changes to terms | Contract (Art. 6(1)(b)); legitimate interests (Art. 6(1)(f)) |
| Marketing | Sending product news and offers; measuring engagement; contacting business prospects about Enterprise plans | Consent (Art. 6(1)(a)) where required; otherwise legitimate interests (Art. 6(1)(f)) with an opt-out in every message |
| Legal compliance and defence | Responding to lawful requests, complying with tax, accounting, sanctions and export control obligations, establishing or defending legal claims | Legal obligation (Art. 6(1)(c)); legitimate interests (Art. 6(1)(f)) |
| Corporate transactions | Due diligence and transfer in a merger, acquisition, financing or reorganisation, under confidentiality restrictions | Legitimate interests (Art. 6(1)(f)) |
5.1 Our legitimate interests assessment
Where we rely on legitimate interests, we have considered whether our interest is outweighed by your rights and freedoms. In each case above we have concluded it is not, because the processing is necessary to deliver or protect a service you have asked for, is limited to what that purpose requires, is subject to the security and retention controls in this policy, does not involve special category data or automated decisions with legal effect, and is described transparently here with an available objection right. You may request a summary of the assessment for any specific processing by writing to privacy@smartvibe.dev, and you may object to the processing as described in Section 12.
5.2 What we do not do
-
We do not sell personal data, and have not done so in the preceding twelve months.
-
We do not share personal data for cross-context behavioural advertising or targeted advertising, and we do not operate advertising networks or place third-party advertising trackers on the authenticated product.
-
We do not use your Prompts, Customer Content or AI Output to train foundation models by default (Section 6).
-
We do not use special category data or children's data for profiling.
-
We do not engage in automated decision-making producing legal effects concerning you (Section 17).
6. AI Processing — Prompts, Code and Model Training
This Section describes the processing that is most specific to our platform. Please read it carefully.
6.1 What happens to a Prompt
When you use an AI feature, we assemble a request comprising your instruction and the context needed to answer it, which may include relevant Project files, the file tree, dependency manifests, database schema, recent errors and earlier turns in the session. We transmit that request over an encrypted channel to a foundation model operated by us or by a Model Provider, receive the AI Output, return it to you and record metering data. We retain the Prompt and AI Output for a limited period to maintain session state, to allow you to review your history, to verify Credit consumption, to debug failures, and to detect abuse.
6.2 Model training — our commitment
We do not use your Prompts, Customer Content, Generated Code, Projects or uploaded files to train, fine-tune or otherwise improve foundation AI models, and we do not permit our Model Providers to do so. We contract with Model Providers on enterprise or API terms that exclude training on data submitted through our accounts, and we seek zero-retention or minimal-retention configurations wherever a provider offers them. Where a provider retains data briefly for its own abuse monitoring, we disclose this in the sub-processor schedule.
We may use your data to train or tune a model only where you have given a specific, informed and separate opt-in, such as submitting an individual conversation for quality review or joining a research programme. Any such opt-in states what data is used and for what purpose, is not a condition of using the Services, and may be withdrawn at any time in respect of future use by writing to privacy@smartvibe.dev. Withdrawal does not require us to retrain a model that has already incorporated data lawfully processed before withdrawal, and we will tell you if that is the case.
6.3 Aggregated and de-identified data
We use aggregated statistics and de-identified telemetry — for example counts of operations by feature, error rates, median latency, token distributions and Credit consumption patterns — to operate, secure, measure and improve the Services and to report on our business. This data does not identify you and is not reverse-engineered to re-identify you, and we will not attempt to re-identify it except to test the effectiveness of de-identification.
6.4 Human review
Our personnel do not routinely read your Prompts or Customer Content. Access by a human occurs only where: (a) you ask us to investigate an issue and access is necessary to do so; (b) an automated abuse-detection signal requires review to confirm a suspected violation of the Acceptable Use Policy or unlawful content; (c) it is necessary to investigate a security incident; or (d) we are legally compelled. Such access is limited to named personnel under confidentiality obligations, is restricted to the minimum data necessary, is logged, and — except where notification would prejudice an abuse or security investigation or is legally prohibited — is notified to you.
6.5 Prompt and log retention
Prompt and AI Output records are retained for the period stated in Section 10. Build logs, terminal history and Live Preview request logs are retained for shorter periods. Where you delete a Project or conversation, associated Prompt records are deleted on the schedule in Section 10.
6.6 Content in Sandboxes and Live Preview
Sandboxes are ephemeral and their filesystems are not backed up. Live Preview URLs are unauthenticated unless you enable an access control feature; anyone with the link can view the running application and any data it displays. Do not place personal data of real individuals into a Live Preview. Preview request logs, including IP addresses of visitors, are retained briefly for security and abuse purposes.
7. Cookies and Similar Technologies
We use strictly necessary cookies to authenticate you, maintain your session, balance load and protect against cross-site request forgery; functional cookies to remember preferences such as theme, editor settings and language; and analytics cookies to understand product usage. We do not use advertising cookies within the authenticated product.
Where required by law — including in the EEA and the UK — we request consent through a consent banner before setting any non-essential cookie, we do not treat inaction as consent, we make declining as easy as accepting, and you may change or withdraw your choices at any time through the cookie settings link in our website footer. Full details of each cookie, its purpose and its lifespan are set out in our Cookie Policy. You can also control cookies through your browser settings, although blocking strictly necessary cookies will prevent you from signing in.
8. Disclosure and Sharing of Personal Data
We disclose personal data only as described below. We do not disclose it to data brokers.
8.1 Sub-processors and service providers
We engage the categories of sub-processor set out below to deliver the Services. Each is bound by a written contract requiring it to process personal data only on our instructions, to apply appropriate security measures, to restrict onward transfer, and to assist with data subject rights. A current, itemised list naming each sub-processor, its processing activity and its location is maintained at smartvibe.dev/legal/subprocessors, and Enterprise customers may subscribe to notifications of changes as provided in the DPA.
| Category | Function | Typical processing locations |
| Cloud infrastructure and hosting | Compute, storage, networking, managed databases, Sandbox execution, backups | India, European Union, United States (region depends on your plan and configuration) |
| AI model providers | Generation of AI Output from Prompts and assembled context | United States, European Union |
| Content delivery and edge security | Content delivery, TLS termination, DDoS mitigation, bot management, WAF | Global edge network including India |
| Payment processing | Card and UPI payment processing, subscription billing, invoicing, tax calculation, fraud screening (Stripe, Razorpay) | India, United States, European Union |
| Identity and authentication | Federated sign-in, SSO, multi-factor authentication delivery | United States, European Union |
| Source control integration | Repository read and write operations you authorise (GitHub) | United States |
| Backend and database platform | Database, authentication and storage services for Projects you connect (Supabase) | Region selected in your Supabase project |
| Transactional email and notifications | Delivery of verification, security, billing and service emails | United States, European Union |
| Product analytics and error monitoring | Usage analytics, session diagnostics, crash and error reporting | United States, European Union |
| Customer support tooling | Ticketing, help centre, in-product messaging | United States, European Union |
| Business operations | Accounting, tax filing, contract management, professional advisers | India |
8.2 Within your organisation
If you use the Services under an organisational Workspace, Workspace administrators can access Account data and Projects in that Workspace, including audit logs of your activity, and can export or delete that data. Data you place in a shared Workspace is visible to members according to the roles configured by the administrator.
8.3 At your direction
When you enable an Integration, publish a Live Preview link, invite a collaborator, or otherwise instruct us to transmit data, we disclose data accordingly. Data you send to a third party at your direction is thereafter governed by that third party's privacy policy.
8.4 Legal and safety disclosures
We may disclose personal data where we reasonably believe it is required to (a) comply with applicable law or a valid legal process, including a court order, subpoena, or lawful request from a law enforcement or regulatory authority, (b) enforce our Terms of Service or Acceptable Use Policy, (c) detect, prevent or address fraud, security or technical issues, or (d) protect the rights, property or safety of SmartVibe, our users or the public, including in an emergency involving a risk of death or serious injury.
We assess each request for validity and scope, we push back on requests that are overbroad or improperly served, we produce only the narrowest set of data responsive to a valid request, and — unless legally prohibited or where notice would create a risk of harm or prejudice an investigation — we will notify you before disclosing your data so that you may seek to challenge the request. Where we act as processor, we will redirect the requesting authority to you where lawfully possible.
8.5 Corporate transactions
If we are involved in a merger, acquisition, financing, reorganisation, insolvency or sale of assets, personal data may be disclosed to advisers and to the counterparty under confidentiality obligations, and may transfer as part of the transaction. Any acquirer will remain bound by this policy in respect of transferred data unless and until you are notified of and, where required, consent to a change.
9. International Transfers of Personal Data
We are established in India and our sub-processors operate in multiple countries, so personal data may be transferred to and processed in countries other than your own, including the United States and countries within the European Economic Area. Those countries may have data protection laws that differ from those of your country.
9.1 Transfers from the EEA, the UK and Switzerland
Where we transfer personal data out of the EEA, the UK or Switzerland, we rely on an appropriate safeguard, being one of: (a) the European Commission's Standard Contractual Clauses (Decision 2021/914), as incorporated into our Data Processing Addendum with the relevant modules completed; (b) the UK International Data Transfer Addendum or the UK IDTA for transfers subject to the UK GDPR; (c) the Swiss addendum recognised by the Swiss Federal Data Protection and Information Commissioner; (d) a finding of adequacy by the relevant authority; or (e) another lawful derogation where applicable. We supplement these with technical and organisational measures including encryption in transit and at rest, access controls, data minimisation and our policy on government access requests set out in Section 8.4, and we carry out transfer impact assessments where required. Copies of the clauses we use are available on request to privacy@smartvibe.dev.
9.2 Transfers under India's DPDP Act
The Digital Personal Data Protection Act, 2023 permits transfer of personal data outside India except to territories notified as restricted by the Central Government. We monitor such notifications and will not transfer personal data to a restricted territory. Where a sectoral law imposes a stricter localisation requirement on data you process, you are responsible for identifying it, and Enterprise customers may agree region-specific storage in an Order Form.
9.3 Data residency options
Depending on your plan, you may be able to select the region in which persisted Customer Content is stored. Region selection does not restrict the location of all processing: AI features may involve transient processing by a Model Provider in another region, and support, billing and security functions may involve access from India. Enterprise customers requiring restrictions on Model Provider location should contact enterprise@smartvibe.dev before purchase.
10. Data Retention
We retain personal data only for as long as necessary for the purposes described in this policy, and then delete or irreversibly anonymise it. Our retention periods are set out below. Where a longer period is required by law, or where data is subject to a legal hold in connection with an actual or anticipated claim, investigation or regulatory request, we retain it for that longer period and delete it once the requirement ends.
| Data | Retention period | Rationale |
| Account and profile data | For the life of the Account, then 30 days after deletion request | Contract performance |
| Customer Content and Projects | For the life of the Account; 30 days after termination for export, deleted from active systems within a further 30 days, and from backups as they expire (max 90 days thereafter) | Contract performance; recovery from accidental deletion |
| Prompts and AI Output records | Up to 90 days from creation, or until you delete the Project or conversation, whichever is earlier | Session state, debugging, billing verification, abuse detection |
| Build, terminal and runtime logs | 30 days | Debugging and support |
| Live Preview request logs | 30 days | Security and abuse detection |
| Security and audit logs | 12 months, or longer for Enterprise as agreed | Security investigation, audit |
| Sandbox filesystem contents | Ephemeral — destroyed on Sandbox termination; not backed up | Nature of the environment |
| Billing records and invoices | 8 years from the end of the relevant financial year | Indian tax, GST and accounting law |
| Support tickets and correspondence | 3 years from closure | Service history, dispute resolution |
| Marketing and consent records | Until you unsubscribe, then a suppression record retained indefinitely | Respecting your opt-out |
| Abuse, fraud and enforcement records | Up to 5 years from action | Preventing repeat abuse, defending claims |
| Deleted account minimal record | Account identifier, plan and enforcement history retained as long as necessary | Preventing re-registration by banned users; legal defence |
11. Security
We maintain a written information security programme with technical and organisational measures appropriate to the risk, including: TLS 1.2+ in transit with HSTS; AES-256 or equivalent encryption at rest for Projects, databases, backups and integration secrets; secrets held in a managed key management service; role-based least-privilege access with mandatory multi-factor authentication for production access and time-bound privilege elevation; quarterly access reviews; logical tenant isolation and constrained Sandbox execution; peer code review, static analysis, dependency and secret scanning in the build pipeline; continuous vulnerability monitoring with independent penetration testing at least annually and defined remediation targets; centralised integrity-protected security logging with anomaly alerting; a tested incident response plan; encrypted automated backups with periodic restoration testing; personnel confidentiality undertakings and annual security training; and security assessment of every sub-processor before engagement. Annex II to our Data Processing Addendum describes these measures in greater detail.
No system can be guaranteed completely secure. Your part matters: use a strong unique password, enable multi-factor authentication, grant Integrations the narrowest scope that works, do not embed production secrets in Projects that will be previewed, review Generated Code for vulnerabilities before deployment, and remove Authorised Users who no longer need access. Please report suspected vulnerabilities to security@smartvibe.dev; our responsible disclosure commitments are in Section 14.1 of the Terms of Service.
11.1 Breach notification
Where we become aware of a personal data breach affecting personal data for which we are the controller, we will notify the competent supervisory authority within seventy-two (72) hours where required by Article 33 of the GDPR, notify the Data Protection Board of India and affected Data Principals as required by the DPDP Act and its rules, and notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. Where we act as processor, we will notify you without undue delay and in any event within seventy-two (72) hours of becoming aware, with the information specified in the DPA, so that you can meet your own obligations.
12. Your Rights Under the GDPR and UK GDPR
If you are in the European Economic Area, the United Kingdom or Switzerland, you have the following rights in respect of personal data for which we are the controller. Where we act as processor, please direct your request to the controller — usually the organisation whose Workspace you use — and we will assist them.
-
Access — obtain confirmation of whether we process your personal data and a copy of it, together with information about the processing.
-
Rectification — have inaccurate personal data corrected and incomplete data completed.
-
Erasure — have personal data deleted where it is no longer necessary, where you withdraw consent and no other basis applies, where you successfully object, or where processing is unlawful.
-
Restriction — require us to limit processing while accuracy is contested, pending an objection, or where you need the data preserved for a legal claim.
-
Portability — receive personal data you provided to us in a structured, commonly used, machine-readable format, and have it transmitted to another controller where technically feasible.
-
Objection — object to processing based on legitimate interests, and object at any time to processing for direct marketing, which we will always honour.
-
Withdraw consent — withdraw consent at any time where processing is based on consent, without affecting the lawfulness of prior processing.
-
Not be subject to automated decision-making — not be subject to a decision based solely on automated processing that produces legal effects concerning you or similarly significantly affects you. See Section 17.
-
Lodge a complaint — complain to your supervisory authority. In the UK this is the Information Commissioner's Office (ico.org.uk). In the EEA it is the authority in your country of residence, place of work or place of the alleged infringement.
12.1 How to exercise your rights
Many rights can be exercised directly in the product: you can edit your profile, export Projects, delete Projects and delete your Account from Account settings, and manage email preferences from any message we send. For anything else, write to privacy@smartvibe.dev with enough information to identify your Account and the right you wish to exercise. We will respond within one month and may extend by up to two further months for complex requests, telling you why. We do not charge a fee unless a request is manifestly unfounded or excessive, and we will explain any charge before applying it. We may ask you to verify your identity — usually by confirming control of the Account email address — and will not ask for more identity data than necessary. If we decline a request in whole or part, we will explain why and how to challenge the decision.
13. Your Rights Under the CCPA and CPRA (California)
This Section applies to California residents and supplements the rest of this policy. Terms used here have the meanings given in the California Consumer Privacy Act as amended by the California Privacy Rights Act.
13.1 Notice at collection
The categories of personal information we collect, the purposes for which we use them, and our retention periods are described in Sections 4, 5 and 10. Mapped to the statutory categories, we collect: identifiers (Cal. Civ. Code §1798.140(v)(1)(A)); commercial information (§(v)(1)(D)); internet or other electronic network activity information (§(v)(1)(F)); geolocation data at city level derived from IP (§(v)(1)(G)); professional or employment-related information (§(v)(1)(I)); and inferences drawn to determine feature preferences (§(v)(1)(K)). Customer Content may contain other categories if you place them there. We do not collect sensitive personal information for the purpose of inferring characteristics; where authentication credentials (a category of sensitive personal information) are collected, they are used only to secure your Account, which is a permitted purpose under §1798.121(d), and we therefore do not offer a separate right to limit.
13.2 Sale and sharing
We do not sell personal information and we do not share it for cross-context behavioural advertising, and we have not done so in the preceding twelve months. We do not have actual knowledge of selling or sharing the personal information of consumers under 16 years of age. We disclose personal information to service providers and contractors for the business purposes described in Section 8, under contracts that restrict their use of it. Because we do not sell or share, we do not offer a "Do Not Sell or Share My Personal Information" link; if this changes we will update this policy and provide the required mechanism before doing so.
13.3 Your California rights
-
Right to know — request the categories and specific pieces of personal information we have collected, the categories of sources, the business or commercial purpose, and the categories of third parties to whom we disclose it, for the 12-month period preceding the request or, on request, beyond it where technically feasible.
-
Right to delete — request deletion of personal information we collected from you, subject to the exceptions in §1798.105(d), including where retention is necessary to complete a transaction, detect security incidents, comply with a legal obligation, or exercise free speech.
-
Right to correct — request correction of inaccurate personal information.
-
Right to opt out of sale or sharing — available if we ever sell or share personal information; we do not.
-
Right to limit use of sensitive personal information — as explained in Section 13.1, we use sensitive personal information only for permitted purposes.
-
Right to non-discrimination — we will not deny you services, charge different prices, or provide a different level of quality because you exercised a privacy right. We do not offer financial incentives for personal information.
13.4 Making a request
Submit requests to privacy@smartvibe.dev with the subject line "California Privacy Request". We will confirm receipt within ten (10) business days and respond substantively within forty-five (45) days, extendable once by a further forty-five days with notice. We verify requests by matching the request to Account records, usually by confirming control of the registered email address; for requests for specific pieces of personal information we may apply a higher standard of verification. An authorised agent may submit a request on your behalf with written permission signed by you, and we may additionally require you to verify your own identity directly. Under California's "Shine the Light" law (Cal. Civ. Code §1798.83) you may request information about disclosures of personal information to third parties for their direct marketing purposes; we make no such disclosures.
14. Your Rights Under India's Digital Personal Data Protection Act, 2023
This Section applies where the Digital Personal Data Protection Act, 2023 ("DPDP Act") applies to our processing. We are a Data Fiduciary in respect of the personal data described in Section 1.1, and a Data Processor in respect of Customer Content.
14.1 Notice and consent
We provide this policy as the notice required by section 5 of the DPDP Act. It sets out the personal data we process, the purposes of processing, how you may exercise your rights, and how you may complain to the Data Protection Board of India. Where we rely on your consent, that consent is sought by a clear affirmative action, is limited to the data necessary for the specified purpose, and may be withdrawn at any time with the same ease with which it was given, by writing to privacy@smartvibe.dev or using the in-product controls. On withdrawal we will cease the relevant processing and delete the personal data within a reasonable period unless retention is required by law. Where we rely on a legitimate use permitted by section 7 — for example providing a service you have requested, complying with a legal obligation, or responding to a medical emergency — we will identify it on request. A notice in English and, on request, in any language specified in the Eighth Schedule to the Constitution of India, is available at smartvibe.dev/legal/privacy.
14.2 Your rights as a Data Principal
-
Right to access information (s.11) — a summary of the personal data we process and the processing activities undertaken, and the identities of other Data Fiduciaries and Data Processors with whom we have shared it, together with a description of the data shared.
-
Right to correction, completion, updating and erasure (s.12) — correction of inaccurate or misleading data, completion and updating of incomplete data, and erasure of personal data no longer necessary for the purpose for which it was processed, unless retention is required by law.
-
Right of grievance redressal (s.13) — to have a readily available means of registering a grievance with us. Our Grievance Officer can be reached at grievance@smartvibe.dev, or via the contact details published at smartvibe.dev/legal/grievance. We will acknowledge within twenty-four (24) hours and respond within the period prescribed by the Act and rules made under it.
-
Right to nominate (s.14) — to nominate another individual to exercise your rights in the event of your death or incapacity. Contact privacy@smartvibe.dev to record a nomination.
You must exhaust the grievance redressal mechanism above before approaching the Data Protection Board of India. You retain the right to complain to the Board thereafter.
14.3 Duties of Data Principals
Section 15 of the DPDP Act places duties on Data Principals, including to comply with applicable law when exercising rights, not to impersonate another person when providing personal data, not to suppress material information when providing personal data for a document or identifier, not to register a false or frivolous grievance or complaint, and to furnish only verifiably authentic information when exercising the right to correction or erasure.
14.4 Children and persons with disability
The Services are restricted to persons aged 18 and over, and we do not knowingly process the personal data of a child or of a person with a disability who has a lawful guardian. We therefore do not undertake behavioural advertising or tracking directed at children. If we become aware that we hold such data without the verifiable consent required by section 9 of the DPDP Act, we will delete it promptly.
14.5 Significant Data Fiduciary obligations
If the Central Government notifies us as a Significant Data Fiduciary under section 10 of the DPDP Act, we will comply with the additional obligations that follow, including appointing a Data Protection Officer based in India who reports to our management, appointing an independent data auditor, and conducting periodic Data Protection Impact Assessments and audits. We will update this policy accordingly.
15. Rights in Other Jurisdictions
Residents of other jurisdictions may have comparable rights, and we apply the substance of the rights described above regardless of where you live. In particular: residents of Virginia, Colorado, Connecticut, Utah, Texas and other US states with comprehensive privacy statutes may exercise rights of access, correction, deletion, portability and opt-out of targeted advertising, sale and profiling (we conduct none of these) and, where a request is denied, may appeal by replying to our decision, after which they may complain to their state Attorney General; residents of Canada may exercise rights under PIPEDA and applicable provincial law; residents of Brazil may exercise rights under the LGPD; residents of Australia may exercise rights under the Privacy Act 1988 and may complain to the OAIC; and residents of Switzerland may exercise rights under the revised FADP. Write to privacy@smartvibe.dev in each case.
16. Children's Privacy
The Services are intended for individuals aged 18 years or older. We do not knowingly collect personal data from anyone under 18, we do not direct the Services to children, and we do not knowingly permit children to create Accounts. If we learn that we have collected personal data from a person under 18, we will delete it and terminate the Account. If you believe a child has provided personal data to us, contact privacy@smartvibe.dev and we will act promptly.
17. Automated Decision-Making and Profiling
We do not make decisions based solely on automated processing that produce legal effects concerning you or similarly significantly affect you. We do use automated systems for limited operational purposes: fraud and abuse scoring, rate limiting, spam and bot detection, content filtering of Prompts against our Acceptable Use Policy, and prioritisation of support tickets. Where an automated control results in a restriction on your Account, you may request human review by writing to support@smartvibe.dev, and a person will review the decision and the reasons for it. We do not carry out profiling for advertising purposes.
18. Do Not Track and Global Privacy Control
There is no common standard for responding to browser "Do Not Track" signals, and we do not currently respond to them. We do honour the Global Privacy Control (GPC) signal where our consent management platform detects it, treating it as a request to opt out of non-essential analytics cookies and, if we ever engage in them, of sale or sharing of personal information.
19. Third-Party Links and Services
The Services may link to third-party websites, documentation, package registries and services, and your Projects may load third-party resources. We do not control those parties and are not responsible for their content, security or privacy practices. Review the privacy policy of any third-party service before providing personal data to it. Personal data you place into a connected third-party service, such as your own Supabase project or GitHub repository, is governed by that service's privacy terms and by your relationship with that provider.
20. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices, the Services, or legal requirements. Where a change is material — for example a new purpose of processing, a new category of recipient, or a change to retention that reduces your protections — we will provide at least thirty (30) days' advance notice by email to the address associated with your Account and by prominent in-product notice, and where the law requires consent for the change, we will obtain it before implementing it. The Effective Date at the head of this policy shows when it was last revised, and we maintain an archive of previous versions at smartvibe.dev/legal/archive. Your continued use of the Services after a change takes effect indicates acceptance of the revised policy, except where consent is required.
21. How to Contact Us and Complain
For any question, request or complaint about this policy or our handling of personal data, contact us first — we would like the opportunity to put things right.
-
Privacy and data protection: privacy@smartvibe.dev
-
Grievance Officer / DPO (India): grievance@smartvibe.dev
-
Security: security@smartvibe.dev
-
Post: SmartVibe AI, Gulmohar Apartment, Panchavati, Nashik, Maharashtra, India
If you are not satisfied with our response you may complain to your data protection authority: the Data Protection Board of India under the DPDP Act; the Information Commissioner's Office in the United Kingdom; your national supervisory authority in the EEA; the California Privacy Protection Agency or California Attorney General in California; or the relevant authority in your jurisdiction.