Legal
Privacy policy
Last updated August 16, 2026. Written for people who'd rather understand what's collected than skip to the bottom.
Who this covers
This policy explains how UIVibes collects, uses and stores personal data when you browse the site, create an account, or subscribe to Pro. It's written with Brazil's LGPD and the EU's GDPR in mind, since UIVibes has users in both regions.
What we collect
- Account data — the email address (and, if you sign in with Google, the name and avatar) tied to your account.
- Authentication cookies —
sb-access-tokenandsb-refresh-token, set by Supabase to keep you signed in. - Billing metadata — subscription status, plan and payment history from AbacatePay. We never see or store your Pix or bank credentials directly; AbacatePay processes the payment itself.
- Usage events — page views, component previews and feature interactions, collected through PostHog for product analytics.
How we use it
- To authenticate you and keep your session working across visits.
- To grant and enforce the access level tied to your account (free vs. Pro).
- To process your subscription payment and reconcile it against your account.
- To understand which components and flows are actually used, so we build the right things next.
- To send account and billing emails — never marketing email without a separate opt-in.
Legal basis for processing
We process account and billing data because it's necessary to perform the contract you enter into when you sign up (LGPD Art. 7, VI; GDPR Art. 6(1)(b)). Usage analytics are processed under our legitimate interest in improving the product (LGPD Art. 7, IX; GDPR Art. 6(1)(f)) — you can object to this at any time, per Section 9.
Cookies
Authentication cookies are strictly necessary — the site doesn't function signed-in without them. PostHog sets analytics cookies to distinguish sessions and users; these aren't used for third-party advertising.
Who we share data with
- Supabase — authentication and database hosting.
- AbacatePay — Pix payment processing and subscription billing.
- PostHog — product analytics (page views and in-app events).
- Vercel — application hosting and content delivery.
We don't sell personal data, and we don't share it with anyone outside these processors except where required by law.
How long we keep it
Account data is kept while your account is active. If you delete your account, we remove personal data within 30 days, except billing records we're required to retain for tax and accounting purposes (typically up to 5 years under Brazilian law). Analytics events are retained in PostHog for as long as they remain useful for product decisions, and are deleted on request.
International transfers
Supabase, PostHog and Vercel may process data on servers outside Brazil. Where that happens, we rely on their standard contractual safeguards for cross-border transfers under LGPD and GDPR.
Your rights
Under LGPD and, where applicable, GDPR, you can ask us to:
- Confirm what personal data we hold about you, and get a copy of it.
- Correct inaccurate or outdated data.
- Delete your account and associated personal data.
- Export your data in a portable format.
- Object to or restrict processing based on legitimate interest, including analytics.
Send any of these requests to hello@uivibes.dev — we'll respond within the timeframe the applicable law requires.
Data security
Data in transit is encrypted (HTTPS/TLS). Access to production data is limited to what's needed to operate the service. We don't store raw payment credentials — those live with AbacatePay, our Pix processor.
Children's privacy
UIVibes is not directed at children, and we don't knowingly collect data from anyone under 18.
Changes to this policy
We may update this policy as the service or the law changes. Material changes will be posted here with a new "last updated" date, and where reasonable, announced by email.
Contact
Questions, requests or complaints about this policy go to hello@uivibes.dev.