Effective date: September 12, 2026
These Terms of Service ("Terms") govern your access to and use of the VibeKit platform, the website at vibekit.bot, the iOS application, the web dashboard at app.vibekit.bot, the CLI, the published npm packages, and any related services (collectively, the "Service"). The Service is operated by VibeKit ("VibeKit", "we", "us"). By using the Service, you agree to these Terms.
VibeKit provides AI-powered software development tooling: each app you create gets its own persistent AI agent, an isolated container hosted on AWS Fargate (us-east-2), a public subdomain at <name>.vibekit.bot, optional custom-domain mapping, and optional GitHub repository integration. You can interact with your agent from the iOS app, the web dashboard, the CLI, or MCP.
The Service is offered "as is." Features change. We may add, modify, or remove functionality. Material changes affecting paying users will be communicated in advance where reasonable.
You must be at least 13 years old to use the Service, or the minimum age required by the laws of your country, whichever is greater. If you use the Service on behalf of an organization, you represent that you have authority to bind that organization to these Terms.
You also represent that you are not located in a country or territory subject to a comprehensive United States embargo, that you do not appear on any US government list of prohibited or restricted parties (including the OFAC Specially Designated Nationals list), and that you will not use the Service in violation of any US export control or sanctions law.
VibeKit lets you route AI requests through your own provider credentials, currently Anthropic API keys (sk-ant-api03-…), Anthropic OAuth tokens from claude setup-token (sk-ant-oat01-…), OpenAI API keys (sk-proj-… and others), and ChatGPT-subscription Codex OAuth tokens.
By submitting any third-party credential to VibeKit, an API key, OAuth token, subscription token, or equivalent, you represent and warrant that the credential is yours (or your organization's), that you are authorized to use it for the purposes for which you are using it via VibeKit, and that doing so does not violate any agreement you have with the issuing provider (e.g. Anthropic, OpenAI, or any other AI service). You are solely responsible for compliance with the terms of the underlying provider, including any restrictions on automated use, sharing, or reselling.
If a provider terminates, throttles, or invoices you because of usage routed through VibeKit, that is between you and the provider. VibeKit has no visibility into your account standing with third-party providers and is not a party to your agreement with them.
Keys are encrypted at rest with AES-256-GCM, using per-user encryption keys derived from a master key via HKDF-SHA256 with your account UUID as salt. Master-key compromise alone does not expose any single user's credentials. Plaintext is held only in process memory at request time and is never written to logs, telemetry, analytics, or backups. You can remove a key at any time from Profile → AI Provider, which deletes the ciphertext from our database.
When you submit a request to your VibeKit agent, the request, including chat messages, file contents, code, and app context relevant to the task, is sent to a third-party AI provider to generate a response.
Each provider operates under its own terms and privacy policy. By using the Service you acknowledge that prompts and context will be transmitted to whichever provider applies to your routing.
Plans (currently Builder and Pro) and add-ons (currently Boost container memory, the database add-on, and per-app Always-On) are monthly subscriptions that renew automatically at the price shown at checkout until you cancel. Prices, included limits, and the current catalog are shown in the product at the time of purchase and may change for future billing periods with at least 30 days' notice.
You agree not to use the Service to:
We may suspend or terminate accounts that violate this section. Egregious abuse may be reported to upstream providers, hosting partners, or law enforcement.
You own the code, files, prompts, and other content you create with the Service ("Your Content"). You grant VibeKit a limited license to host, process, transmit, and display Your Content only as necessary to operate the Service for you, e.g., running your code in your Fargate container, serving your subdomain, sending prompts to AI providers, syncing to your linked GitHub repo, and showing you your data in the dashboard. We don't claim ownership of Your Content, we don't sell it, and we don't use it to train our own models (we don't train models).
You're responsible for Your Content. Don't upload anything you don't have rights to.
Apps you build and host on the Service may themselves collect data from their own visitors and users (for example through signup forms, databases, or email features). As between you and VibeKit, you are the owner and controller of your app's end-user data. VibeKit processes that data only as your hosting infrastructure. You are solely responsible for your app's compliance with applicable law with respect to its end users, including posting your own privacy policy where required, obtaining any required consents, honoring deletion requests, and complying with email-marketing law for messages your app sends. VibeKit does not pre-screen user apps and is not responsible for content or data practices of apps operated by users.
Apps are private to your account unless you mark one as public. If you do, you grant VibeKit a non-exclusive license to display that app's name, the description you wrote for it, and its live URL in the public gallery at vibekit.bot and in VibeKit's own social-media and marketing posts, for as long as the app stays public. We do not post screenshots or the contents of the app. Turning the public setting off ends the license for future use, though posts already published elsewhere are not recalled.
We respond to notices of alleged copyright infringement that comply with the Digital Millennium Copyright Act. If you believe content hosted on the Service infringes your copyright, send a notice to [email protected] with the subject "DMCA Notice" including: (1) identification of the copyrighted work; (2) the URL of the allegedly infringing material; (3) your contact information; (4) a statement of good-faith belief that the use is unauthorized; (5) a statement, under penalty of perjury, that the notice is accurate and you are authorized to act for the copyright owner; and (6) your physical or electronic signature. We may remove or disable access to the identified material, notify the user who posted it, and terminate the accounts of repeat infringers. Counter-notices may be sent to the same address and must satisfy 17 U.S.C. § 512(g)(3).
Agent responses are generated by third-party language models. They may be inaccurate, incomplete, or unsafe to deploy without review. You are responsible for reviewing any code, configuration, or output produced by your agent before relying on it in production or shipping it to users. The same model output, given identical prompts, can vary between calls.
We do not warrant that AI output is correct, fit for any particular purpose, free of intellectual-property issues, or compliant with the laws of any jurisdiction in which you operate.
Connections let you link a third-party account (for example Gmail, Slack, Notion, GitHub, Jira, HubSpot, Stripe) to a specific VibeKit app so that app's agent can use it on your behalf. Linking is handled by our integration provider, Composio, through that provider's standard OAuth flow. VibeKit does not receive your account password or the OAuth token used to establish the connection; Composio holds that token, and we keep a record that a connection exists.
Connected accounts are not read-only. An agent acting on a connected account can create, modify, send, publish, and delete data in that account, and for accounts that support it, can take actions that move money or create financial obligations, such as creating a charge, issuing an invoice, cancelling a subscription, or placing an order. You choose which accounts to connect and which app to connect them to. Connecting an account is your authorization for that app's agent to act in it.
Some connected-account tools can return sensitive credentials, including API keys, access tokens, passwords, private keys, or database connection strings. These tools remain available because retrieving or administering credentials may be the task you want the agent to perform. Before VibeKit executes one, the Service requires a separate confirmation phrase from a later message authored by you and warns that the credential will pass through VibeKit and Composio, enter the app's agent transcript, and be transmitted to the third-party AI provider handling that turn. By providing the confirmation phrase, you explicitly authorize that disclosure and accept the risk of the credential appearing in the conversation context. Do not confirm unless you own or are authorized to access the credential and accept that processing.
Agents are probabilistic and can act incorrectly. An agent may misread your instruction, act on stale information, take an action you did not intend, or be influenced by content it reads inside a connected account. Content that reaches an agent from a connected account, such as an email body, an issue title, a message, or a document, may contain text designed to manipulate the agent into taking actions you did not ask for. This is a known and unsolved class of risk across the AI industry, commonly called prompt injection, and it is not fully preventable. We instruct agents to confirm with you before actions that leave your account or destroy data, and to treat content they read as information rather than as instructions, but these are behavioral instructions to a model, not technical guarantees, and they can fail.
You are solely responsible for actions taken in your connected accounts through the Service, and you accept the risk of connecting any account. Do not connect an account where an incorrect action would cause harm you are not prepared to absorb. If you connect an account that can move money, we display a "can spend" marker on that account in the product before you connect it. You can disconnect any account at any time from the app's Connections screen, which revokes the agent's access going forward; disconnecting does not reverse actions already taken.
You represent and warrant that you own or are authorized to connect each account, that connecting it does not violate your agreement with that provider, and that you are permitted to allow automated or agentic access to it. Some providers restrict third-party or automated access in their own terms. Compliance with those terms is your responsibility, and a provider's decision to suspend, restrict, or invoice your account as a result of activity routed through the Service is between you and that provider.
Actions taken in a connected account are performed against that provider's systems and are governed by that provider's terms and privacy policy, not ours. VibeKit is not a party to, and does not control, the underlying provider relationship, and cannot reverse, refund, or recover an action once that provider has executed it.
The catalog of connectable applications is provided as a convenience and may change without notice. Third-party names and logos shown in the Service are the property of their respective owners and are used solely to identify the applications you can connect. Their appearance does not indicate sponsorship, endorsement, or affiliation.
The Service integrates with third parties including but not limited to: Anthropic, OpenAI, OpenRouter, Google (Sign in with Google; Gemini via OpenRouter), DeepSeek, xAI (Grok via OpenRouter), the operators of OpenRouter's free-model pool, Perplexity (agent web search, via OpenRouter), Stripe, Supabase, Cloudflare, GitHub, Vercel (legacy paths), Namecheap, AWS, Apple (App Store and Sign in with Apple), and Composio (connected-account integrations, see Section 10). Their terms govern their portions of the Service.
VibeKit-hosted apps run as standalone AWS Fargate tasks in us-east-2, served at <name>.vibekit.bot behind a shared nginx layer. You may map a custom domain to your app via the in-product flow.
Idle sleep. An app that is not always-on is stopped after about 60 minutes without traffic and started again on the next visit, which adds a short delay to that first request. Always-on apps stay running; always-on is included in Builder and Pro up to the plan's slot limit and available per app as an add-on. Uptime monitors and platform probes do not count as traffic.
Subdomains are issued first-come, first-served and may be reclaimed if (a) your account is terminated, (b) the subdomain impersonates VibeKit or another brand in a way that creates user confusion, or (c) the subdomain is unused for an extended period after we have notified you.
We aim for high availability but make no uptime guarantee. Maintenance windows, third-party outages (AI providers, AWS, Cloudflare, etc.), and emergency patches may interrupt access. AWS occasionally retires the underlying task an app runs on; when that happens the app is started on a fresh task at its next visit, so a retired app can be unavailable until someone visits it (always-on apps are restarted automatically).
You are responsible for maintaining your own backups of anything you cannot afford to lose. Deleting an app permanently destroys its container, workspace, files, environment variables, and uploads, and the Service is not a system of record. A copy of the app's chat transcript is kept after deletion for the quality review described in the Privacy Policy and is removed when you delete your account or on request. Linking a GitHub repository to your app is the supported way to keep an independent copy of your code.
You can stop using the Service and delete your account at any time from the dashboard. We can suspend or terminate access for material breach of these Terms, prolonged inactivity (12+ months for free accounts with no balance), or to comply with legal obligations.
On termination, your Fargate tasks stop, your subdomain mapping is removed, agent sessions and transcripts (including archived transcripts of deleted apps) are deleted, your workspace and file uploads are deleted within 30 days, and any unused refundable credit balance is processed according to Section 6. Your linked GitHub repository (if any) and any custom-domain registration you purchased through Namecheap remain yours, VibeKit does not delete external resources you own.
THE SERVICE IS PROVIDED "AS IS" AND "AS AVAILABLE," WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, OR STATUTORY, INCLUDING IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, NON-INFRINGEMENT, AND ANY WARRANTIES ARISING FROM COURSE OF DEALING OR USAGE OF TRADE. VIBEKIT DOES NOT WARRANT THAT THE SERVICE OR AI OUTPUT WILL BE UNINTERRUPTED, ERROR-FREE, OR ACCURATE.
TO THE MAXIMUM EXTENT PERMITTED BY LAW, VIBEKIT WILL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, OR PUNITIVE DAMAGES, OR ANY LOSS OF PROFITS, REVENUE, DATA, OR GOODWILL, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES. VIBEKIT'S TOTAL CUMULATIVE LIABILITY FOR ANY CLAIM RELATED TO THE SERVICE IS LIMITED TO THE GREATER OF (A) THE AMOUNT YOU PAID VIBEKIT IN THE TWELVE MONTHS PRECEDING THE CLAIM, OR (B) USD $50.
You agree to indemnify and hold VibeKit harmless from any third-party claim arising out of (a) Your Content, (b) your use of the Service, (c) your breach of these Terms, (d) your representations about BYOK credentials in Section 4a, (e) your violation of any third-party provider's terms via the Service, or (f) any action taken in an account you connected under Section 10, including actions taken by an agent on your behalf.
These Terms are governed by the laws of the State of Delaware, United States, without regard to its conflict-of-laws principles. Nothing in this section prevents either party from seeking injunctive relief in a court of competent jurisdiction, or from bringing an individual claim in small-claims court where it qualifies.
Informal resolution first. Before filing any claim, you agree to email [email protected] with a description of the dispute and give us 30 days to resolve it informally.
Binding individual arbitration. If informal resolution fails, any dispute arising out of or relating to these Terms or the Service will be resolved by binding arbitration administered by the American Arbitration Association under its Consumer Arbitration Rules, before a single arbitrator, on an individual basis. The arbitration may be conducted by video or written submission, and for claims under $10,000 you may choose a hearing in your home county. The arbitrator may award the same relief a court could, to you individually. Judgment on the award may be entered in any court of competent jurisdiction. The Federal Arbitration Act governs this clause. Any claim that is found not to be arbitrable will be brought exclusively in the state or federal courts located in Delaware, and you consent to that jurisdiction.
30-day opt-out. You can reject this arbitration clause by emailing [email protected] with the subject "Arbitration opt-out" and the email address on your account within 30 days of first accepting these Terms. Opting out does not affect any other part of these Terms.
Class action and jury waiver. To the maximum extent permitted by law, any dispute will be resolved on an individual basis only. YOU AND VIBEKIT EACH WAIVE ANY RIGHT TO A JURY TRIAL AND ANY RIGHT TO PARTICIPATE IN A CLASS ACTION, CLASS ARBITRATION, OR OTHER REPRESENTATIVE PROCEEDING. If this waiver is found unenforceable for a particular claim, that claim (and only that claim) proceeds in court.
We may update these Terms. Material changes will be announced on the platform with reasonable notice (typically 30 days for paying users). Continued use of the Service after the effective date constitutes acceptance.
Questions about these Terms? Email [email protected].