Vybe

Effective Date: May 4, 2026 | Last Updated: May 19, 2026

Vybe ("we," "us," or "our") is an AI-powered photo and video creation app. This Privacy Policy explains what data we collect, how we use it, who we share it with, and your rights regarding that data.

By using Vybe, you agree to the practices described in this policy. If you do not agree, please discontinue use of the app. This Privacy Policy is incorporated into and forms part of our Terms of Use.


πŸ”‘ Key Points

If you don't read anything else, here's what matters most:


1. Who We Are

Vybe is operated from the Republic of TΓΌrkiye. We are the data controller for personal data processed through the Service.

Contact: trendylab.app@gmail.com

We will respond to verifiable privacy requests within 30 days.


2. Information We Collect

Vybe is designed to be used without creating an account in the traditional sense. We do not require β€” and do not collect β€” your name, email address, phone number, or any other contact details. Vybe assigns your device a randomly generated anonymous identifier so we can manage your generation history, coin balance, and subscription. This identifier cannot be used to identify you personally.

We collect the following categories of information when you use the Service:

Category Data Types How Collected
Anonymous Account ID A randomly generated Firebase user ID assigned to your device. Not linked to your name, email, or any personal identifier. Automatically, on first launch
Device Install Identifier A random UUID generated by the App and stored locally in iOS Keychain. Used solely to prevent abuse of the welcome-bonus offer (one bonus per device). Not shared with advertisers, data brokers, or used for cross-app tracking. Persists across app uninstall until you reset your device. Generated locally on first launch
Profile Preferences Gender selection (used to personalize the catalog), notification preferences When you set them in the App
Visual Records Photos, images, and videos you upload for AI generation, along with the prompts you submit When you tap "Generate"
Generation History Filter / pack used, model used, generation status, timestamps, prompts Automatically, when you use AI features
Customer Transaction Data Subscription tier, state, expiration date, coin balance, redeemed promotional codes When you subscribe or purchase coins
Engagement Data Daily streak, referral code, referral count Automatically, as you use the App
Device & Process Security Data Device type, operating system, IP address, app version, push notification token, IDFV (Identifier for Vendors), session timestamps, crash logs Automatically collected
Advertising Identifier (IDFA) Apple's IDFA, used only for measuring ad campaign performance via our advertising partner (Meta). Only collected if you grant App Tracking Transparency permission. If you decline, this value is not collected and is not shared with any advertising partner. Only when you grant ATT permission
Facebook Anonymous Identifier A randomly generated identifier issued by the Facebook SDK on first launch. Allows our advertising partner (Meta) to measure ad-campaign performance for users who declined ATT, without exposing your device's IDFA. Cannot be used to identify you personally. Automatically, on first launch
Usage Data Events and screens viewed within the App (e.g. onboarding completed, paywall viewed, content purchased) Automatically via analytics

We do not collect:


3. How We Use Your Information

We use the information we collect for the following purposes:

3.1 Provide and Operate the Service

3.2 Improve the Service

3.3 Security and Compliance

3.4 Communications

3.5 Marketing (with consent only)

You can opt out of marketing communications at any time via your device settings or by contacting us.


4. AI Processing of Your Photos and Videos

When you tap "Generate" within the App:

  1. The selected photo or video is uploaded from your device to our secure cloud storage on Firebase Storage.
  2. We send the file (via a signed, time-limited URL) to our AI processing partner, fal.ai, under a written data processing agreement.
  3. fal.ai processes the file using the selected AI model and returns the generated result.
  4. We download the result and save it to your account so it appears in your Results tab. Your original uploaded file is then deleted from our servers β€” typically within seconds of the AI returning a result. Any stragglers from failed generations are removed by an automated daily cleanup within 24 hours.
  5. You may save the result to your device's Photos library at any time using the Save button. Results that you do not delete manually are automatically removed from our servers after 30 days.

fal.ai operates as a data processor. They are contractually obligated to process your content only to fulfill your generation request and not for any other purpose, including model training.


5. Face Data

If your uploaded photo or video contains a face, we process facial information solely to enable AI generation.

5.1 What We Collect

The selected photo or video file you upload for AI generation. We do not collect or generate biometric templates, faceprints, or facial geometry measurements as standalone identifiers.

5.2 Purpose

Face data is processed exclusively to deliver the AI generation service you request. It is not used for identity verification, facial recognition, surveillance, or authentication.

5.3 Retention

5.4 Sharing

Face-containing files are shared only with fal.ai under a data processing agreement, solely to perform the AI generation you requested. We do not sell, lease, or share face data with advertisers, data brokers, or any third party for purposes other than fulfilling the requested service.

5.5 Third-Party Storage of Face Data

5.6 What We Do NOT Do With Face Data


6. SDK and Analytics Partners

The Service uses the following third-party SDKs. These SDKs do not access your uploaded photos, videos, or face data.

Provider Purpose Data Accessed
Firebase Authentication (Google) Anonymous device authentication Randomly generated user ID β€” no email, name, or social login data
Firebase Firestore (Google) Account state and generation metadata Anonymous user ID, job records, subscription state, preferences
Firebase Storage (Google) File storage for uploads and results Uploaded photos, videos, and generated outputs
Firebase Analytics (Google) Usage and engagement metrics Anonymous device identifier, screen views, in-app events
Firebase Crashlytics (Google) Crash reporting Crash logs, device model, OS version, app state
Firebase App Check (Google) Abuse and bot prevention Device attestation tokens
RevenueCat Subscription and entitlement management; server-side dispatch of purchase events to advertising partners Anonymous user ID, App Store transaction identifiers, subscription state, Facebook anonymous ID, IDFA (if granted)
Meta (Facebook) SDK + Conversions API Install attribution and ad campaign optimization. We use Meta's iOS SDK for install/session attribution and the Meta Conversions API (dispatched server-side via RevenueCat) for purchase event measurement. Client-side automatic event logging is disabled β€” only the events listed in Section 2 ("Usage Data") are shared. Anonymous user ID (hashed), Facebook anonymous ID, IDFA (if ATT granted), device attributes (OS, locale, app version), purchase amount and currency, event timestamps
Mixpanel Product analytics β€” funnels, retention, feature engagement (no advertising). Hosted on Mixpanel's EU data residency region. Anonymous user ID, screen views, in-app events, device class, app version
fal.ai AI photo and video generation Photos and videos you submit for generation

We may add or change service providers as the Service evolves. Any new or replacement provider will be subject to similar privacy and security obligations, and material changes will be reflected in this Privacy Policy.

Advertising data minimization. We do not share your photos, videos, face data, prompts, or generated outputs with any advertising partner. The data shared with Meta is limited to anonymous identifiers and the purchase/conversion events necessary to measure ad campaign performance. Mixpanel receives behavioral product-analytics events only and is not used for advertising.


7. Technical and Administrative Security Measures

We apply industry-standard safeguards to protect your data:

In the event of a personal data breach that poses a risk to user rights, we will notify affected users and the relevant supervisory authority in accordance with applicable law.


8. Data Retention

We retain personal data only as long as necessary for the purposes described in this Privacy Policy or as required by applicable law:


9. Your Rights

Subject to applicable law, you have the following rights regarding your personal data:

9.1 General Rights

9.2 In-App Controls

9.3 How to Exercise Your Rights

Send a verifiable request to trendylab.app@gmail.com with sufficient information to identify your account. We will respond within 30 days. If we are unable to fulfill a request, we will explain why.


10. KVKK (Turkish Personal Data Protection Law No. 6698)

If you are located in the Republic of TΓΌrkiye, your personal data is processed in accordance with the Personal Data Protection Law No. 6698 ("KVKK"). Under Article 11 of KVKK, you have the right to:

To exercise these rights, please submit a clear, verifiable request to trendylab.app@gmail.com with proof of identity. We will respond within 30 days.


11. GDPR (European Economic Area)

If you are located in the European Economic Area, the United Kingdom, or Switzerland, the General Data Protection Regulation ("GDPR") applies to our processing of your personal data.

Legal bases for processing:

Activity Legal Basis
Providing the Service (account, generation) Contract performance (GDPR Art. 6(1)(b))
Security, fraud prevention, service improvement Legitimate interests (GDPR Art. 6(1)(f))
Marketing communications Consent (GDPR Art. 6(1)(a))
Legal and tax compliance Legal obligation (GDPR Art. 6(1)(c))
AI processing of photos and videos Contract performance β€” processing is necessary to deliver the requested service

International transfers: Your data may be transferred to and processed in countries outside the EEA (including the United States, where fal.ai and certain Google Cloud services operate). We rely on Standard Contractual Clauses approved by the European Commission and other appropriate safeguards.

You have the right to lodge a complaint with your local supervisory authority.


12. California Residents (CCPA / CalOPPA)

If you are a California resident, the California Consumer Privacy Act ("CCPA") and the California Online Privacy Protection Act ("CalOPPA") provide you the following rights:

We do not sell the personal information of our users for money. We do share a limited set of advertising identifiers and conversion events with Meta for advertising purposes as described above; you control this through iOS tracking settings. We never share your photos, videos, face data, prompts, or generated outputs with any advertising partner.

To exercise these rights, contact us at trendylab.app@gmail.com. We will respond within 45 days.


13. Children's Privacy

The Service is intended for users aged 13 and older. Users between the ages of 13 and 17 must have permission and supervision from a parent or legal guardian.

We do not knowingly collect personal information from children under 13. If we learn that we have collected personal information from a child under 13, we will delete it promptly. If you believe a child under 13 has provided us with personal information, please contact us at trendylab.app@gmail.com.

If you are a parent or legal guardian and you become aware that your child has provided us with personal information without your consent, please contact us so we can take appropriate action.


14. Cookies and Similar Technologies

The Service is delivered as a mobile application and does not use traditional browser cookies. However, our SDK partners (e.g., Firebase Analytics, Meta SDK) use device identifiers, advertising identifiers (IDFV, IDFA), the Facebook anonymous identifier, and similar technologies to maintain sessions and measure usage and advertising performance.

App Tracking Transparency (ATT). Apple requires us to ask for your permission before accessing your IDFA for cross-app advertising measurement. The first time you open Vybe (after onboarding), iOS will show a system prompt asking whether to allow tracking:

You can change your decision at any time:


15. Push Notifications

We may send push notifications to communicate service-related events (subscription, account, security alerts) and, if you have opted in, marketing updates. You can disable push notifications at any time via your device settings.


16. International Data Transfers

We process personal data primarily on Google Cloud infrastructure (Firebase) and via fal.ai, which may operate servers outside the country where you reside. By using the Service, you consent to the transfer of your information to and processing in countries that may have different data protection laws than your country of residence. Where applicable, we rely on Standard Contractual Clauses or other valid transfer mechanisms.


17. Sale of Business and Affiliates

If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or part of our assets, your personal data may be transferred as part of that transaction, subject to standard confidentiality protections and notice obligations. The acquirer will be required to honor the commitments made in this Privacy Policy or provide notice and a meaningful opportunity to opt out before any material change to processing.

We may share information with our corporate affiliates (entities under common control or ownership), subject to the same protections in this Privacy Policy.


18. Third-Party Links

The Service may contain links to third-party websites or services we do not control. This Privacy Policy does not apply to those websites or services. We encourage you to review the privacy policies of any third party before submitting personal information.


19. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal obligations. When we make material changes, we will:

Your continued use of the Service after changes become effective constitutes acceptance of the updated Privacy Policy. If you do not agree to changes, you must stop using the Service and may delete your account.


20. Contact Us

For privacy-related questions, requests, or complaints, please email:

trendylab.app@gmail.com

We will respond to verifiable requests within 30 days (or 45 days for CCPA requests), as required by applicable law.


Β© 2026 Vybe. All rights reserved.