Privacy Policy

Last updated August 26, 2026

VibeMeASite ("VibeMeASite", "we", "us") is a chat-first tool for building and maintaining a website through conversation with an AI assistant (Claude or another MCP-compatible client). This policy explains what information we collect, why, and how it's protected — including when you connect a Google Calendar or iCloud Calendar account to use the appointment-booking feature.

VibeMeASite is operated as an independent product; there is no separate registered company behind it at this time. Contact admin@vibemeasite.com with any question about this policy or your data.

Information we collect

Account & identity. Your email address, used to log you in via a one-time link (no password) and to identify your site across sessions.

Site content. The business details, pages, navigation, branding (colors/logo/text), and visual sections you describe or generate while building your site.

Connected hosting accounts. If you claim your site to your own infrastructure, an encrypted access token for your Vercel account and your Postgres database connection string — used only to create and manage the hosting resources you asked for.

Calendar connections (if you use the booking widget). If you connect Google Calendar, we store an encrypted OAuth access token and refresh token. If you connect iCloud Calendar, we store your Apple ID and an encrypted app-specific password (never your real Apple ID password). These credentials are used only to:

  • Check your calendar's free/busy times, so the booking widget only offers real openings; and
  • Create, update, or delete a calendar event when a visitor books, reschedules, or cancels an appointment through your booking widget.

We never read, store, or share the content of your other calendar events beyond the free/busy time ranges needed for this check.

Booking widget visitor data. If your site has a booking widget, we collect the name, email address, and any additional fields you've configured (e.g. phone number, notes) from visitors who book an appointment, solely to manage that appointment (confirmation, calendar sync, cancellation, and rescheduling).

SMS / text message opt-in. If you register for a webinar or otherwise opt in to text messages from VibeMeASite, we collect your name, business name, email address, and mobile phone number to send the updates, reminders, and demo links you agreed to receive. You can stop these messages anytime by replying STOP, or get help by replying HELP.

Mobile phone numbers and opt-in data collected for SMS notifications will not be sold, rented, or shared with third parties for marketing purposes.

VibeMeASite's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements.

How we use this information

  • To provide the core service: building, deploying, and maintaining your site through chat.
  • To operate the booking widget: computing availability and keeping your calendar and the widget in sync.
  • To send you service emails (login links, booking confirmations, appointment notifications) via our email provider, Resend.
  • To keep the service secure and prevent abuse (e.g. rate-limiting login attempts).

We do not sell your data, and we do not use it for advertising. We don't run any advertising trackers or analytics cookies on this site.

Who we share data with

We use the following service providers to operate VibeMeASite. Each only receives the specific data needed to perform its function, and each has its own privacy practices:

  • Google — Calendar API, only if you connect Google Calendar.
  • Apple — iCloud CalDAV, only if you connect iCloud Calendar.
  • Vercel — application hosting.
  • Neon — database hosting.
  • Resend — transactional email delivery.
  • Cellpy — the content/block platform your site's visual sections are stored on.
  • Anthropic (Claude) or OpenAI (ChatGPT) — only if you connect VibeMeASite through one of these platforms; see below.

Connecting via Claude or ChatGPT

VibeMeASite can be connected as a remote tool ("connector" or "app") inside Claude or ChatGPT, so the assistant can build and manage your site on your behalf during a conversation. See how to connect and what the connector can do.

What connecting collects. The one-time login link flow (same as logging in directly) collects your email address, used to issue an access token scoped to your VibeMeASite account. No password, payment details, or other personal information is requested during connection.

What each tool call can read or write. Once connected, the assistant can call the same tools described on the connector page — reading or changing only your own site's content, settings, and connections (domains, calendars, form destinations, collaborators). No tool reads data belonging to any other VibeMeASite account. Upgrading to a paid plan is available through the Claude connector; on the ChatGPT connector this step happens on vibemeasite.com instead, not inside the chat, per OpenAI's own rules for connected apps.

What the AI platform itself sees. Anthropic (for Claude) or OpenAI (for ChatGPT) relays your requests to VibeMeASite and receives the tool responses as part of your conversation with their assistant — the same way any other message in that conversation is visible to them. That data is governed by Anthropic's or OpenAI's own privacy policy, not this one; we don't control what either platform retains from your chat history.

Disconnecting. Removing the connector in Claude's or ChatGPT's settings revokes its access token immediately — no further tool calls can be made with it. This doesn't delete your site or account; use the deletion request under Data retention and deletion below for that.

Data retention and deletion

Calendar credentials are deleted immediately when you disconnect a calendar. Other account and site data is retained for as long as your account/site exists. You can disconnect a calendar, cancel individual bookings, or ask us (admin@vibemeasite.com) to delete your account and associated data at any time.

Security

All connection credentials (Vercel tokens, database URLs, Google/iCloud calendar credentials, Cellpy tokens) are encrypted at rest (AES-256-GCM) and transmitted only over HTTPS. Access is limited to the systems that need it to operate the feature you've connected.

Children's privacy

VibeMeASite is not directed to children under 13, and we do not knowingly collect information from them.

Changes to this policy

If this policy changes materially, we'll update the date at the top of this page. Continued use of VibeMeASite after a change means you accept the updated policy.

Contact

Questions, requests, or concerns about this policy or your data: admin@vibemeasite.com.