Vibeworld Privacy Policy

Last updated: July 22, 2026

The honest summary: Vibeworld is a game made of real coding sessions. When you opt a session in, parts of it become visible to every other player — that is the product, not a side effect. We use that data to run the game and for nothing else. We don't sell it, we don't profile you with it, we don't train AI models on it. Sessions are private by default; nothing leaves your machine until you say so. Questions you deliberately ask a district resident are a separate, clearly labeled AI feature described below.

1. What we collect, and when

Nothing is transmitted unless you explicitly opt a Claude Code session in with /world on. For opted-in sessions only, the game client (the "harness" running on your machine) transmits:

2. Who can see it

Other players. Everything above is broadcast into the shared world — prompts and chats to players near you, your presence to anyone who walks by. Treat anything you share as public. District-resident questions are not broadcast to other players; they are processed by OpenAI to generate the resident's private reply.

3. Redaction (best effort, not a guarantee)

Before anything leaves your machine, the harness scrubs: API keys and tokens (AWS, GitHub, Slack, OpenAI-style, JWTs, bearer tokens), private keys, long hex/base64 strings, email addresses, and phone numbers. Prompts that mention street addresses, SSNs, or passport numbers are dropped entirely. Redaction is a seatbelt, not a guarantee — the real control is that you choose which sessions go public. Don't type secrets into public sessions.

4. What we do NOT do

Your data is used for one purpose only: running the game you're playing. It is never used for anything else — not sold, not rented, not shared for anyone else's purposes, not advertised with, not profiled, not mined, and not used to train AI models. Concretely:

5. Retention — what we store, exactly

The world is largely ephemeral: prompts and chats live as in-game speech bubbles and expire in seconds; presence data lives in server memory and is garbage-collected minutes after you leave. Standard web-server logs rotate briefly. Our one durable database stores exactly this:

We never store: prompt or reply text, tool arguments, code, diffs, GPS or addresses, card numbers, bank accounts, or passwords (none exist). Resident conversation history lives only in the open game tab and disappears on reload; our OpenAI request sets store: false. OpenAI may retain limited abuse-monitoring logs under its API data policy.

6. AI district residents

Each district has an optional resident you can question about that district, Vibeworld, its features, and possible future versions. The server sends the short conversation to OpenAI's Responses API with a district-specific prompt. The API key and system prompt remain server-side. Residents cannot inspect your screen, account, local files, repository, or coding session, and their answers may be wrong. OpenAI states that API inputs and outputs are not used to train its models by default; its own API data policy applies.

7. Payments

Purchases and bounty funding are processed by Stripe. Your card details go to Stripe, never to us; solver payout details (bank, identity) go to Stripe, never to us. Stripe's own privacy policy applies. We keep only the checkout/payment references needed to issue licenses, release bounty payouts and process refunds.

8. Your choices

9. Children

Vibeworld is not directed at children under 13, and we do not knowingly collect their data.

10. Changes

If this policy changes, the date above changes, and material changes will be announced in the world and on the landing page before they take effect.

← back to vibeworld