Privacy Policy
Read the current terms and your choices below.
Release note: the AI data-sharing permission and withdrawal controls described below are prepared for the next iOS update and are not yet in the current App Store version. Until that update is available, you can avoid AI transfers by not using VibeAI; local notes remain available. The data-flow disclosures below also describe the current service.
Scope and contact
This notice covers the VibeMemo iOS app and vibememo.cc. VibeMemo provides private note taking and optional online AI and support services. Contact the VibeMemo developer through https://vibememo.cc/help/docs/contact for privacy questions or access, correction and deletion requests. No VibeMemo account is required. VibeMemo is operated by BERKAY BAHCECI.
Notes, iCloud and device permissions
Notes and confirmed voice transcripts are stored on your device. Optional iCloud sync uses Apple CloudKit under your Apple account. Locked note content is encrypted before storage; biometric templates are not accessible to VibeMemo. Microphone and speech permissions are requested when you use transcription. Apple Speech may process audio on Apple servers depending on language and device support; on-device-only recognition is not guaranteed. VibeMemo does not save an audio recording. A transcript becomes note text when you save it and can be sent to AI if you choose that action.
Optional AI processing and recipients
VibeAI sends the selected note title, body, requirements, technology choices, platform and language instructions through the VibeMemo gateway on Cloudflare to Groq or OpenRouter. If a provider fails, the same request may be sent to another of these providers. OpenRouter can route to different underlying model providers. On first use, the app explains this transfer and asks for permission. Your choice is remembered; VibeAI does not have a separate on/off setting and does not ask again on every request. New permission is needed if the disclosed processing materially changes. You can withdraw permission from Settings > Legal Documents > Privacy Policy. This stops future AI and quota requests from this app, but does not recall data already sent or cancel an in-flight request. Normal note taking remains available.
Service records, reports and website support
The gateway stores a random installation identifier from Keychain, plan and quota counts, and service timestamps in Cloudflare D1. Cloudflare processes IP addresses and request metadata for delivery, security and rate limiting. If you submit an AI report, its reason, optional details, prompt/response excerpts, provider, language and installation identifier are stored in D1; report details and response excerpts are also sent to our support workspace on Slack. Website contact forms send your name, email, subject, message, language and page address through Cloudflare to Slack for a reply. Do not include secrets or unnecessary personal information. We do not use advertising SDKs, sell data or track you across other companies’ apps and websites. Website language preferences may be stored locally in your browser.
Provider safeguards and international processing
Our gateway does not persist ordinary AI prompts or results in its application database and does not use them to train a VibeMemo model. Groq may retain content for reliability or abuse investigations for up to 30 days, subject to legal exceptions. OpenRouter requests require providers marked as not collecting data and as Zero Data Retention endpoints; if none is available, the request falls back to Groq or fails without relaxing those filters. This routing control is not a promise that every service stores no metadata or that legal exceptions do not apply. Gemini is disabled in server routing. Processing can occur outside your country, including the United States. Do not submit secrets or unnecessary sensitive, confidential or personal information. Current provider policies are linked below.
Retention and deletion
Local notes remain until you delete them; Trash keeps recoverable copies until permanent deletion or the configured automatic cleanup. Manage synced copies through VibeMemo and Apple iCloud settings. Removing the app does not necessarily remove iCloud data or Keychain identifiers. Ordinary gateway prompts are transient; installation, quota and submitted report records currently have no automatic expiry and remain until manually deleted. Support messages remain in the Slack workspace until deleted under its retention settings. Security nonce records expire after five minutes and rate-limit records after their short windows. For server-side deletion, use the contact page and include your installation identifier if available, or the approximate report time; never send your note text just to identify a request. We will assess the request, verify it with proportionate information and explain any legal retention requirement. Provider logs and backup copies follow the provider’s deletion cycle.
Your choices and policy changes
You can use notes without AI permission, decline or revoke microphone/speech access in iOS Settings, and manage optional iCloud sync. Depending on applicable law you may request access, correction, deletion, restriction, portability or object to processing, and complain to your data protection authority. Contact VibeMemo for records we control; we will direct requests about Apple or provider-controlled data to the appropriate service when needed. Withdrawing permission does not affect prior lawful processing. Material changes to AI data recipients or purposes require a renewed permission request in an updated app. The current notice and its date are available in the app and on our website.