VibeStarter

Privacy policy

Effective as of August 30, 2026

This is a translation of the French version, which prevails in case of discrepancy.

Data controller

The controller of the personal data collected via vibestarter.pro is Ethan Dorme--Talandier, acting as a sole proprietor (entrepreneur individuel) trading under the name « VibeStarter » (SIRET 104 303 797 00013), publisher of the website (see legal notice). For any question regarding your personal data: contact@vibestarter.pro.

Cookies

The website only uses first-party cookies set by vibestarter.pro and does not rely on any advertising network or third-party tracking solution. Optional audience-measurement and affiliate cookies are only set or read after you agree.

Cookies strictly necessary for operation

  • lang stores the chosen language (fr / en). Duration: 1 year.
  • vibestarter_session encrypted session cookie inaccessible to JavaScript, set on sign-in. Keeps you authenticated. Maximum duration: 30 days, renewed while the account is actively used.
  • vs_auth only tells the browser whether a session exists and whether it has the administrator role, so the correct navigation is shown immediately. Contains no email address or access token. Same duration as vibestarter_session, up to 30 days.
  • vs_plus_checkout marks for 15 minutes that a VibeStarter Plus checkout was opened, so the correct state can be displayed after payment returns.

Audience measurement cookies — with your consent

  • vs_aid randomly generated pseudonymous identifier. Used to count visitors and link steps in the same journey. With your permission and once signed in, subsequent events may be linked to your account identifier. Duration: 30 days.
  • vs_utm stores the UTM parameters (source, campaign) of the last ad link that brought you to the website, to measure the effectiveness of each campaign. Duration: 30 days.
  • vs_funnel remembers the entry page you arrived through (e.g. a page shared on social media), so we can measure the journey that follows. Duration: 30 days.

Affiliate attribution cookies — with your consent

  • vs_aff_slug stores the slug of the last affiliate whose link you followed, so their tier and commission can be calculated if you purchase. Duration: 30 days.
  • vs_aff stores the same affiliate's Bonzai payment identifier as a compatibility value while the program transitions. Duration: 30 days.

Preference cookies

  • vs_consent stores your audience-measurement and affiliate-attribution choices separately, so they can be applied without asking on every visit. This cookie is strictly necessary to honour your choice. Duration: 180 days.

Local and session storage

In addition to cookies, your browser stores the following items locally. This data stays in your browser and is never sent to our servers.

  • vs_idea_lead (localStorage) remembers that the free-video form was submitted, or the date and number of times you dismissed it, so the waiting period before showing it again is respected. Persists until browser storage is cleared.
  • vs_idea_lead_seen (sessionStorage) prevents the free-video form from being shown more than once in the same tab. Deleted when the tab closes.
  • vs_v3_confetti_played (sessionStorage) prevents the launch animation from replaying on every navigation in the same tab. Deleted when the tab closes.

The data collected via these cookies is sent to our self-hosted application server api.vibestarter.pro when you accept audience measurement — with no transfer to an advertising network. You can change your choices at any time through “Manage my cookies” in the footer; withdrawal immediately stops the relevant reads and writes and deletes the corresponding optional cookies.

Personal data processed

The processing operations described below are carried out when you interact with the features of the website.

User account

A VibeStarter account is created when you make a purchase on the third-party platform Bonzai. The data stored on our application server is: email address, name (when provided), an internal numeric identifier and, where applicable, a Discord identifier if you choose to link your Discord account (see below).

Legal basis: performance of the contract (article 6-1-b of the GDPR). Retention period: your account is kept as long as it remains active, and for at most 3 years from your last sign-in (CNIL recommendation), after which it is automatically deleted. You may also request its deletion at any time via the self-service tools (see the « Your rights » section below) or at the contact address above.

Magic link sign-in

Sign-in is performed via a one-time link sent to your email address (no password). No identifier or password is stored. The link automatically expires 10 minutes after being issued.

Discord linking (optional)

If you choose to link your Discord account from the « My account » page, we store the Discord identifier associated with your VibeStarter account, your Discord display name and the cumulative voice presence time on the community server, for the sole purpose of managing your access to community spaces. This linking is optional, relies on your consent (article 6-1-a of the GDPR) and may be withdrawn at any time.

Desktop application and third-party AI services (BYOK)

The VibeStarter desktop application runs official third-party AI coding agents (Claude Code, Codex, Antigravity, OpenCode), which you sign into with your own provider account or subscription: those requests are sent directly from your machine to the provider, without going through our infrastructure, and we neither store nor relay your provider credentials or access tokens. Asset generation follows a different path, whichever plan you are on: your request goes through our application server (api.vibestarter.pro), which performs the call to the provider — with the API key you supply, transmitted for that sole purpose and held in memory for the duration of your session, never written to a database; or, if you use VibeStarter Plus, with our own provider accounts. VibeStarter is not responsible for the processing carried out by those services. However, the resulting assets, and their upload to Roblox, do involve our application server, as described in the « Asset bank » and « Roblox connection » sections below. Each of these third-party services has its own terms of service and privacy policy, which you are responsible for consulting.

Asset bank

The assets you generate or import in the application are sent to our application server (api.vibestarter.pro) to be prepared and then uploaded to Roblox. Sharing with the community (the « Share my generated / imported assets » settings) is enabled by default: these assets are kept in the shared Bank and made available to other members (license detailed in article 4.3 of the Terms). You can disable it at any time in the application settings. Once sharing is disabled, the assets are only kept for the time needed to finalize the upload — one hour, and at most six hours after they were last used — then permanently deleted from our servers.

Cloud projects and collaboration

If you create a Cloud project or collaborate on another member's project, the project content (code, configuration, version history) is synchronized through our application server so it can be shared between participants, each of whom has access to it. Your creator identity (username) and your presence (connection status, Roblox Studio activity) are visible to the other participants of the project. This data is retained for as long as the Cloud project exists and is deleted with it. Legal basis: performance of the contract (article 6-1-b of the GDPR).

Roblox connection

To publish your creations on Roblox, the application connects to your Roblox account via the « Sign in with Roblox » authorization (OAuth 2.0): it is the only path for uploading assets. The OAuth permissions requested are strictly limited to reading and writing assets (asset:read, asset:write) to upload the generated content, and your creator identity (openid, profile) to identify the target account. Creating developer products and game passes falls outside those permissions: it requires a separate Roblox Open Cloud API key, which you create and provide yourself, and which also serves to provision in-game measurement.

The two credentials follow different regimes. The Roblox OAuth token never passes through your machine: it is issued to our application server, which stores it encrypted and uses it on your behalf; the application only holds a link indicator. Your Open Cloud API key, by contrast, is stored locally in your operating system's secure keychain and transmitted to our application server api.vibestarter.pro, which performs the corresponding Roblox API call on your behalf, then returns the identifier of the created asset. These accesses are used solely to carry out the actions you explicitly trigger. Legal basis: performance of the contract (article 6-1-b of the GDPR).

This connection is used only to publish on Roblox: we do not read the content of your existing Roblox experiences, your players' data, or your revenue, and we do not store your Roblox password. The storage and possible sharing of the assets you generate are governed by the « Asset bank » section above and by article 4.3 of the Terms. You can revoke this access at any time from your Roblox account settings, or by deleting the key in the application. Processing carried out by Roblox is governed by Roblox Corporation's privacy policy.

Audience measurement and technical logging

Our application server retains technical logs (errors, requests) for a maximum of 18 days. IP addresses are masked therein (/24 in IPv4, /48 in IPv6) and email addresses are hashed. If you accept audience measurement, page views, clicks, campaign sources, country and device categories are retained under a pseudonymous identifier for no more than 25 months. Once signed in, subsequent events may be linked to your account identifier. Legal basis: your consent (article 6-1-a of the GDPR). If the account is deleted, that identifier is detached from retained events.

Affiliate attribution

When you follow an affiliate link without having chosen yet, a dedicated page explains how attribution works before anything is written. If you accept, the last affiliate clicked is remembered on your device for 30 days and passed to checkout when you purchase so their commission can be calculated. If you refuse, no persistent attribution takes place. Legal basis: your consent (article 6-1-a of the GDPR). Withdrawal deletes the cookies for future purchases; it does not alter a commission already attached to a completed transaction.

Payments and billing

Transactions, invoices, VAT and payment data are handled by Inflow Pay (French SAS, 58 rue de Monceau, 75008 Paris, VAT No. FR54928877349), acting as the legal seller (Merchant of Record) and as an independent data controller for those operations. The checkout is operated by the Bonzai technical platform (Frog Tech OÜ, Estonia). No payment data (card number, etc.) transits through vibestarter.pro. See Inflow Pay's website for their privacy policy and terms of sale.

Sign-up for the free video (marketing)

When you enter your email address in the « free video » form shown on the site, we use it to send you the private access link to the video, then a short sequence of emails introducing VibeStarter. Legal basis: your consent (article 6-1-a of the GDPR), collected when you submit the form. Data processed: your email address, the date and page of submission, and proof of consent. Retention: 3 years from your last contact. You can withdraw your consent at any time via the unsubscribe link in every email (immediate effect) or by contacting us.

Minors

In France, the digital age of consent is set at fifteen (15) (article 45 of the French Data Protection Act, adopted under article 8 of the GDPR). The Service is intended for persons who have reached that age, and the terms of use make it a condition of access to an account.

Where processing relies on your consent — the audience-measurement cookies and the free-video sign-up described above — that consent is valid, for a person under fifteen, only if it is given or authorised by the holder of parental authority. Processing necessary for the performance of the contract (account, access to the Service, billing) does not rely on consent and is not affected by this rule.

We do not collect a date of birth and carry out no age verification beyond the declaration collected at the time of the order. The holder of parental authority of a child under fifteen may at any time request access to the data concerning them, its rectification or its erasure, at the contact address given at the top of this policy. The request is handled without any need to state a reason: the account is deleted and the associated data erased as described in the « Your rights » section.

Processors and transfers outside the EU

The following providers process personal data on our behalf:

  • Vercel Inc. — hosting of the website pages (United States). Technical data: request logs, IP address, HTTP headers. Transfer framed by the EU-US Data Privacy Framework (DPF) (articles 44 et seq. of the GDPR).
  • Hostinger — hosting of our application server api.vibestarter.pro (server physically located in France, no transfer outside the EU). Data stored: user accounts, audience measurement events.
  • Resend, Inc. — delivery of transactional emails (sign-in links, account deletion notifications) and of the « free video » email sequence (United States). For that sequence, your email address is also stored as a contact at Resend to manage delivery and unsubscription. Data transmitted: recipient's email address and message content. Transfer framed by the Standard Contractual Clauses adopted by the European Commission (article 46 of the GDPR).
  • Discord — provider of the community platform (Discord Inc., United States). If you choose to link your Discord account, your Discord identifier is exchanged via the OAuth protocol to manage your access to the community server. Discord adheres to the EU-US Data Privacy Framework (DPF). See the Discord privacy policy.
  • Inflow Pay — legal seller (Merchant of Record) and independent data controller for transactions, invoices, VAT and payment data (French SAS, 58 rue de Monceau, 75008 Paris, VAT No. FR54928877349). See their website.
  • Bonzai — technical checkout platform (Frog Tech OÜ, Estonia), independent data controller for data collected at checkout (email address, creator-account identifiers). See their privacy policy.
  • Roblox Corporation — recipient and independent data controller for the content you publish on your own Roblox account (United States). When you trigger an upload, your creator identifier and the relevant content are transmitted to Roblox via the Open Cloud API, under your authorization. See the Roblox privacy policy.

Your rights

Pursuant to the General Data Protection Regulation (GDPR) and the French Data Protection Act, you have the following rights:

  • Right of access and portability — you may at any time download all of your data in JSON format from your « My account » page (self-service export), or request it by email.
  • Right of rectification — you may modify your name directly from your « My account » page. The email address is updated through the magic-link sign-in flow.
  • Right to erasure — you may delete your account directly from your « My account » page. Deletion takes effect immediately (your account is deactivated and you are signed out); a grace period of 30 days applies before final deletion, during which you may cancel the request via the link received by email. After that, data is permanently erased or anonymized.
  • Rights to restriction, objection and withdrawal of consent — you may exercise these at any time by contacting us. Withdrawal of Discord consent is also done from your « My account » page.

For any request that cannot be made via self-service, or for any question, contact: contact@vibestarter.pro. You will receive a response as soon as possible and at the latest within one month.

Any action taken in connection with the exercise of your rights (export, deletion, rectification) is recorded in an internal audit log, in which your email address is stored in hashed form. This log is kept for 3 years for evidence purposes, pursuant to article 30 of the GDPR.

If, after contacting us, you consider that your rights are not respected, you may lodge a complaint with the French data protection authority (CNIL), cnil.fr/en/plaintes.