Claims you can verify

Trust Center

A direct account of how Vibe Together approaches creator ownership, privacy, AI, security, vendors, and responsible disclosure.

Effective

Our commitments

  • Your original music stays yours; we take only the limited license needed to operate the Service.
  • We do not sell personal information or use it for cross-context behavioral advertising.
  • Future Heritage does not use creator content to train its own machine-learning models.
  • We use notice-driven copyright enforcement and do not claim automated clearance or perfect detection.
  • We describe the safeguards and certifications we actually have, not the ones we may pursue later.

Data boundaries

Raw voice-sketch microphone input and raw Web MIDI messages are designed to stay in your browser. Musical results you commit can be synchronized. Audio is uploaded only when you intentionally record or upload a sample or use a workflow that requires server conversion or storage. Privacy Policy

Security practices

  • Supabase Auth identities and application-user records are resolved on the server for ownership decisions.
  • Owner-only actions use object-level authorization checks; private storage uses scoped or time-limited access.
  • Public and mutating endpoints use request validation, body limits, security headers, rate limits, and generic error handling appropriate to the route.
  • Privileged credentials stay on the server and are not intentionally shipped in browser code.
  • Security-sensitive releases use automated tests, secret scanning, dependency auditing, and database integrity checks.

No system is perfectly secure. Vibe Together is not currently represented as SOC 2, ISO 27001, PCI DSS service-provider, HIPAA, or FedRAMP certified. Stripe handles payment-card collection through its hosted payment systems.

AI boundaries

AI supports focused creative tools such as sample generation and musical assistance. Vibe Together is not a prompt-to-song service, and the musical decisions remain with the creator. Relevant prompts and composition context may be sent to OpenAI or ElevenLabs. We do not claim ownership of creator output or use creator content to train our own models. Provider terms and restrictions still apply, and no tool can promise universal clearance.

Core service providers

  • Supabase: authentication, Postgres database, and private object storage.
  • Railway: application and realtime-service hosting.
  • Stripe: hosted checkout, payments, refunds, disputes, and entitlement signals.
  • Resend: service, community, and marketing email.
  • OpenAI: requested AI music and sound-patch features.
  • ElevenLabs: requested sound generation.
  • UserJot: feedback and optional feedback screenshots.
  • Sanity: public blog and editorial content.
  • Google Analytics: optional traffic, campaign, content, and conversion measurement with advertising features disabled.

Report a security issue

Email security@makevibestogether.com with a clear description, affected URL or feature, reproduction steps, and potential impact. Do not access other users’ data, degrade the Service, use social engineering, or publicly disclose an unresolved issue before we have had a reasonable opportunity to investigate.

We do not currently operate a paid bug-bounty program or promise a specific response time. Good-faith reports that respect these boundaries are welcome. Contact