Effective Date: May 4, 2026 | Last Updated: May 19, 2026
Vybe ("we," "us," or "our") is an AI-powered photo and video creation app. This Privacy Policy explains what data we collect, how we use it, who we share it with, and your rights regarding that data.
By using Vybe, you agree to the practices described in this policy. If you do not agree, please discontinue use of the app. This Privacy Policy is incorporated into and forms part of our Terms of Use.
If you don't read anything else, here's what matters most:
Vybe is operated from the Republic of TΓΌrkiye. We are the data controller for personal data processed through the Service.
Contact: trendylab.app@gmail.com
We will respond to verifiable privacy requests within 30 days.
Vybe is designed to be used without creating an account in the traditional sense. We do not require β and do not collect β your name, email address, phone number, or any other contact details. Vybe assigns your device a randomly generated anonymous identifier so we can manage your generation history, coin balance, and subscription. This identifier cannot be used to identify you personally.
We collect the following categories of information when you use the Service:
| Category | Data Types | How Collected |
|---|---|---|
| Anonymous Account ID | A randomly generated Firebase user ID assigned to your device. Not linked to your name, email, or any personal identifier. | Automatically, on first launch |
| Device Install Identifier | A random UUID generated by the App and stored locally in iOS Keychain. Used solely to prevent abuse of the welcome-bonus offer (one bonus per device). Not shared with advertisers, data brokers, or used for cross-app tracking. Persists across app uninstall until you reset your device. | Generated locally on first launch |
| Profile Preferences | Gender selection (used to personalize the catalog), notification preferences | When you set them in the App |
| Visual Records | Photos, images, and videos you upload for AI generation, along with the prompts you submit | When you tap "Generate" |
| Generation History | Filter / pack used, model used, generation status, timestamps, prompts | Automatically, when you use AI features |
| Customer Transaction Data | Subscription tier, state, expiration date, coin balance, redeemed promotional codes | When you subscribe or purchase coins |
| Engagement Data | Daily streak, referral code, referral count | Automatically, as you use the App |
| Device & Process Security Data | Device type, operating system, IP address, app version, push notification token, IDFV (Identifier for Vendors), session timestamps, crash logs | Automatically collected |
| Advertising Identifier (IDFA) | Apple's IDFA, used only for measuring ad campaign performance via our advertising partner (Meta). Only collected if you grant App Tracking Transparency permission. If you decline, this value is not collected and is not shared with any advertising partner. | Only when you grant ATT permission |
| Facebook Anonymous Identifier | A randomly generated identifier issued by the Facebook SDK on first launch. Allows our advertising partner (Meta) to measure ad-campaign performance for users who declined ATT, without exposing your device's IDFA. Cannot be used to identify you personally. | Automatically, on first launch |
| Usage Data | Events and screens viewed within the App (e.g. onboarding completed, paywall viewed, content purchased) | Automatically via analytics |
We do not collect:
We use the information we collect for the following purposes:
You can opt out of marketing communications at any time via your device settings or by contacting us.
When you tap "Generate" within the App:
fal.ai operates as a data processor. They are contractually obligated to process your content only to fulfill your generation request and not for any other purpose, including model training.
If your uploaded photo or video contains a face, we process facial information solely to enable AI generation.
The selected photo or video file you upload for AI generation. We do not collect or generate biometric templates, faceprints, or facial geometry measurements as standalone identifiers.
Face data is processed exclusively to deliver the AI generation service you request. It is not used for identity verification, facial recognition, surveillance, or authentication.
Face-containing files are shared only with fal.ai under a data processing agreement, solely to perform the AI generation you requested. We do not sell, lease, or share face data with advertisers, data brokers, or any third party for purposes other than fulfilling the requested service.
The Service uses the following third-party SDKs. These SDKs do not access your uploaded photos, videos, or face data.
| Provider | Purpose | Data Accessed |
|---|---|---|
| Firebase Authentication (Google) | Anonymous device authentication | Randomly generated user ID β no email, name, or social login data |
| Firebase Firestore (Google) | Account state and generation metadata | Anonymous user ID, job records, subscription state, preferences |
| Firebase Storage (Google) | File storage for uploads and results | Uploaded photos, videos, and generated outputs |
| Firebase Analytics (Google) | Usage and engagement metrics | Anonymous device identifier, screen views, in-app events |
| Firebase Crashlytics (Google) | Crash reporting | Crash logs, device model, OS version, app state |
| Firebase App Check (Google) | Abuse and bot prevention | Device attestation tokens |
| RevenueCat | Subscription and entitlement management; server-side dispatch of purchase events to advertising partners | Anonymous user ID, App Store transaction identifiers, subscription state, Facebook anonymous ID, IDFA (if granted) |
| Meta (Facebook) SDK + Conversions API | Install attribution and ad campaign optimization. We use Meta's iOS SDK for install/session attribution and the Meta Conversions API (dispatched server-side via RevenueCat) for purchase event measurement. Client-side automatic event logging is disabled β only the events listed in Section 2 ("Usage Data") are shared. | Anonymous user ID (hashed), Facebook anonymous ID, IDFA (if ATT granted), device attributes (OS, locale, app version), purchase amount and currency, event timestamps |
| Mixpanel | Product analytics β funnels, retention, feature engagement (no advertising). Hosted on Mixpanel's EU data residency region. | Anonymous user ID, screen views, in-app events, device class, app version |
| fal.ai | AI photo and video generation | Photos and videos you submit for generation |
We may add or change service providers as the Service evolves. Any new or replacement provider will be subject to similar privacy and security obligations, and material changes will be reflected in this Privacy Policy.
Advertising data minimization. We do not share your photos, videos, face data, prompts, or generated outputs with any advertising partner. The data shared with Meta is limited to anonymous identifiers and the purchase/conversion events necessary to measure ad campaign performance. Mixpanel receives behavioral product-analytics events only and is not used for advertising.
We apply industry-standard safeguards to protect your data:
In the event of a personal data breach that poses a risk to user rights, we will notify affected users and the relevant supervisory authority in accordance with applicable law.
We retain personal data only as long as necessary for the purposes described in this Privacy Policy or as required by applicable law:
Subject to applicable law, you have the following rights regarding your personal data:
Send a verifiable request to trendylab.app@gmail.com with sufficient information to identify your account. We will respond within 30 days. If we are unable to fulfill a request, we will explain why.
If you are located in the Republic of TΓΌrkiye, your personal data is processed in accordance with the Personal Data Protection Law No. 6698 ("KVKK"). Under Article 11 of KVKK, you have the right to:
To exercise these rights, please submit a clear, verifiable request to trendylab.app@gmail.com with proof of identity. We will respond within 30 days.
If you are located in the European Economic Area, the United Kingdom, or Switzerland, the General Data Protection Regulation ("GDPR") applies to our processing of your personal data.
Legal bases for processing:
| Activity | Legal Basis |
|---|---|
| Providing the Service (account, generation) | Contract performance (GDPR Art. 6(1)(b)) |
| Security, fraud prevention, service improvement | Legitimate interests (GDPR Art. 6(1)(f)) |
| Marketing communications | Consent (GDPR Art. 6(1)(a)) |
| Legal and tax compliance | Legal obligation (GDPR Art. 6(1)(c)) |
| AI processing of photos and videos | Contract performance β processing is necessary to deliver the requested service |
International transfers: Your data may be transferred to and processed in countries outside the EEA (including the United States, where fal.ai and certain Google Cloud services operate). We rely on Standard Contractual Clauses approved by the European Commission and other appropriate safeguards.
You have the right to lodge a complaint with your local supervisory authority.
If you are a California resident, the California Consumer Privacy Act ("CCPA") and the California Online Privacy Protection Act ("CalOPPA") provide you the following rights:
We do not sell the personal information of our users for money. We do share a limited set of advertising identifiers and conversion events with Meta for advertising purposes as described above; you control this through iOS tracking settings. We never share your photos, videos, face data, prompts, or generated outputs with any advertising partner.
To exercise these rights, contact us at trendylab.app@gmail.com. We will respond within 45 days.
The Service is intended for users aged 13 and older. Users between the ages of 13 and 17 must have permission and supervision from a parent or legal guardian.
We do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, we will delete it promptly. If you believe a child under 13 has provided us with personal information, please contact us at trendylab.app@gmail.com.
If you are a parent or legal guardian and you become aware that your child has provided us with personal information without your consent, please contact us so we can take appropriate action.
The Service is delivered as a mobile application and does not use traditional browser cookies. However, our SDK partners (e.g., Firebase Analytics, Meta SDK) use device identifiers, advertising identifiers (IDFV, IDFA), the Facebook anonymous identifier, and similar technologies to maintain sessions and measure usage and advertising performance.
App Tracking Transparency (ATT). Apple requires us to ask for your permission before accessing your IDFA for cross-app advertising measurement. The first time you open Vybe (after onboarding), iOS will show a system prompt asking whether to allow tracking:
You can change your decision at any time:
We may send push notifications to communicate service-related events (subscription, account, security alerts) and, if you have opted in, marketing updates. You can disable push notifications at any time via your device settings.
We process personal data primarily on Google Cloud infrastructure (Firebase) and via fal.ai, which may operate servers outside the country where you reside. By using the Service, you consent to the transfer of your information to and processing in countries that may have different data protection laws than your country of residence. Where applicable, we rely on Standard Contractual Clauses or other valid transfer mechanisms.
If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our assets, your personal data may be transferred as part of that transaction, subject to standard confidentiality protections and notice obligations. The acquirer will be required to honor the commitments made in this Privacy Policy or provide notice and a meaningful opportunity to opt out before any material change to processing.
We may share information with our corporate affiliates (entities under common control or ownership), subject to the same protections in this Privacy Policy.
The Service may contain links to third-party websites or services we do not control. This Privacy Policy does not apply to those websites or services. We encourage you to review the privacy policies of any third party before submitting personal information.
We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal obligations. When we make material changes, we will:
Your continued use of the Service after changes become effective constitutes acceptance of the updated Privacy Policy. If you do not agree to changes, you must stop using the Service and may delete your account.
For privacy-related questions, requests, or complaints, please email:
We will respond to verifiable requests within 30 days (or 45 days for CCPA requests), as required by applicable law.
Β© 2026 Vybe. All rights reserved.