Trust & Legal

Privacy Policy

This policy explains what Vibe Together collects, what stays on your device, which service providers process data, and the choices available to you.

Effective

1. Who we are

Vibe Together is operated by Future Heritage LLC, a New York limited liability company ("Future Heritage," "Vibe Together," "we," "us," or "our"). This policy applies to makevibestogether.com, our web application, and related services that link to it (the "Service").

Vibe Together is currently intended for people in the United States who are at least 18 years old.

2. Information we collect

We collect information you provide, information created through your use of the Service, and limited technical information needed to operate and protect it.

  • Account and identity data: email address, Supabase authentication identifier, connected sign-in provider, account status, display name, emoji or avatar configuration, creator handle, bio, genres, and social links.
  • Music and collaboration data: live-session state, nodes, wires, sources, music settings, presence and cursor state, editable Vibes, snapshots, sound patches, sample references, published compositions, descriptions, discovery metadata, visibility, remix lineage, and engagement counters.
  • Audio and uploaded content: samples you upload or intentionally record, generated samples, temporary share recordings, rendered exports, and the metadata needed to store, play, convert, or attribute those files.
  • AI feature data: prompts, selected settings, relevant composition or patch context, provider responses, generated audio, and safety or error information.
  • Payment and entitlement data: Stripe customer, checkout, payment, refund, dispute, and entitlement records. We do not receive or store your full payment-card number.
  • Communications and feedback: support messages, marketing and community email choices, delivery or suppression events, UserJot feedback, and screenshots you choose to attach.
  • Technical and usage data: IP address, request and security logs, browser or device information, session and composition identifiers, feature events, referral information, and a first-party browser visitor identifier that is hashed before analytics storage. When optional analytics are enabled, Google Analytics also receives sanitized page paths, campaign and referral information, limited device information, selected conversion events, and pseudonymous client and session identifiers.

3. What stays local and what is transmitted

  • Voice sketch: raw microphone audio used to derive notes stays in the browser; derived musical information may be added to and synchronized with your session.
  • Recorded samples: when you deliberately record or upload a sample, the audio is uploaded to private storage associated with your account.
  • MIDI: raw device messages are handled locally; notes, velocity, duration, and graph changes you commit may be synchronized or saved.
  • Share capture: the capture flow records the intended composition output, not microphone input or interface sounds. A WebM file may be temporarily uploaded for compatibility conversion.
  • Browser storage: localStorage and Supabase browser storage may hold theme, tutorial, display, session-history, analytics preferences, first-party analytics, referral, and authentication information on your device. When allowed, Google Analytics uses _ga and _ga_* cookies for pseudonymous traffic and session measurement.

4. How we use information

  • Provide, synchronize, restore, publish, export, and support the Service.
  • Authenticate accounts, preserve ownership, enforce usage limits, and provide paid entitlements.
  • Operate collaboration, creator profiles, public listening, remixing, discovery, and sharing.
  • Generate requested AI suggestions, sound patches, or samples and apply safety checks.
  • Process payments, receipts, refunds, disputes, and required transaction records.
  • Send transactional service messages and non-transactional email updates when your account preference is on.
  • Measure reliability and product use, prevent fraud or abuse, investigate incidents, and enforce our policies.
  • Comply with law, protect rights and safety, and resolve disputes.

5. Visibility and public content

Live drafts and account sample libraries are not public by default. Publishing creates an immutable listener page. Public compositions may appear in the Community Mixtape, creator profiles, search, previews, and social cards. Unlisted compositions are not intended for public discovery, but anyone with the link may access and remix them inside Vibe Together.

Creator profiles can publicly show your handle, display name, avatar, bio, genres, social links, plaques, statistics, and published catalog. Do not publish information you want to keep private.

6. AI processing

Requested AI features may send your prompt and relevant composition or sound-patch context to OpenAI or ElevenLabs so they can return the requested result. Future Heritage does not use your creator content to train its own machine-learning models. Our providers process data under their own terms, privacy policies, retention settings, and account configuration; we do not promise that provider processing is equivalent to local processing.

We may store prompts, generated results, provider attribution, and limited safety or diagnostic data when needed to deliver the feature, keep your library available, investigate abuse, or resolve errors.

7. Service providers and disclosures

We disclose data to vendors only as needed for their role: Supabase for authentication, Postgres, and storage; Railway for application hosting; Stripe for payments; Resend for email; Google Analytics for optional traffic, content, campaign, and conversion measurement; OpenAI for AI music and sound-patch features; ElevenLabs for requested sound generation; UserJot for feedback; and Sanity for public editorial content.

We may also disclose information when required by law, to respond to valid legal process, to protect users or the Service, to investigate fraud or security incidents, or as part of a merger, financing, acquisition, or sale of assets subject to appropriate protections.

8. Cookies and browser storage

We use essential browser storage for authentication, preferences, session continuity, and feature state. Optional first-party analytics and Google Analytics 4 support aggregate product, traffic, content, campaign, and conversion measurement. Analytics are allowed by default for the current United States launch unless you decline them or your browser sends Global Privacy Control. You can change this choice through Analytics preferences in the footer or on this page. The choice applies to the current browser and device, not your account as a whole, and does not require an account or a Supabase request. Declining removes the first-party analytics identifier and available _ga and _ga_* cookies and prevents optional analytics from running. A signed, HttpOnly, SameSite=Lax referral cookie may last up to 30 days so a shared-link visit can be attributed without exposing the token to browser scripts. We keep Google advertising, remarketing, and ad-personalization signals disabled and do not use third-party advertising cookies.

9. Retention

We keep information for the shortest period reasonably needed for the purposes described above, subject to operational, security, contractual, and legal requirements. Current product retention rules include:

  • Inactive live sessions and first-party analytics events may be deleted after 90 days.
  • Google Analytics event and user data is configured for a retention period of up to 14 months, subject to Google's aggregation and deletion behavior.
  • Drafts you delete may remain soft-deleted for about 30 days before permanent removal.
  • Temporary Share WebM uploads and compatibility MP4 files are scheduled for deletion after about 24 hours.
  • Temporary audio-export jobs and download authorization can expire after about 30 minutes.
  • Signed sample-playback links generally expire after about one hour; expiration of a link does not delete the underlying private sample.
  • Published compositions, creator profiles, account records, purchases, consents, and generated or uploaded library assets remain while needed to provide the Service, preserve transaction or rights records, comply with law, or until they are deleted or removed under an applicable process.

Backups and security records may persist for a limited additional period. De-identified or aggregated information may be retained when it can no longer reasonably identify you.

10. Your choices and privacy rights

For the initial United States launch, Email updates are on by default when you create a permanent account. They cover onboarding, product news, community spotlights, challenges, and offers. You can turn them off from Account or use the unsubscribe link in any non-transactional email. Transactional messages such as sign-in links, receipts, refunds, security notices, and publish confirmations are separate.

  • Turn email updates on or off from your account page, or use the unsubscribe link in any non-transactional email.
  • Unpublish compositions you own and delete eligible editable Vibes or library items through available product controls.
  • Clear local browser data through your browser settings. Doing so may sign you out or remove local history and preferences.
  • Open Analytics preferences from the footer or this page to allow or decline optional first-party analytics and Google Analytics in this browser.
  • Ask to access, correct, delete, or receive information about your personal data by emailing privacy@makevibestogether.com.
  • Appeal a privacy-request decision by replying to the decision. You may also contact the appropriate regulator or state attorney general.

We may need to verify your identity before completing a request. We may retain information where law permits or requires, including transaction, fraud-prevention, security, copyright, and dispute records. Authorized agents must provide evidence of authority. Contact

11. Security and processing location

We use reasonable technical and organizational safeguards appropriate to the Service, including authenticated ownership checks, private storage with time-limited access, request validation, rate limits, restricted server credentials, and security monitoring. No online service can guarantee absolute security. Trust Center

Future Heritage operates from the United States. Our providers may process information in the United States and other locations where they or their subprocessors operate, subject to their contractual and legal safeguards.

12. Age requirement

The Service is not directed to children and is available only to people who are at least 18. If you believe a person under 18 has provided personal information, contact us so we can investigate and take appropriate action.

13. Changes and contact

We may update this policy as the Service changes. We will post the new version and effective date and provide additional notice when a change is material and the law requires it.

Privacy
privacy@makevibestogether.com
Operator
Future Heritage LLC
Mail
Future Heritage LLC ยท 3 Court Square, Long Island City, NY 11101