← Back to VibeReskin

Privacy Policy

Last updated: August 14, 2026

VibeReskin ("Service") is operated by Oleksandr Sitnikov ("we", "us", "our"). This Privacy Policy describes the data flows in the current public website and private reskin tool. It does not replace rights or obligations that may apply under local law.

1. Data We Collect

Data TypeWhatWhy
Waitlist dataEmail address submitted through the public waitlist form, plus the submission time recorded by the serverManage the waitlist and contact you about access
Tool contentUploaded assets, optional reference images, filenames, prompts, style briefs, and generated outputsRun the processing operations you request
Operation recordsJob status and history, selected mode and provider, timestamps, estimated provider cost, and error informationOperate the tool, show results, diagnose failures, and track provider spend
Private access dataHTTP Basic Auth credentials presented to the reverse proxy and authentication-related request metadataRestrict access to the private tool
Technical and analytics dataPage views and request metadata that may include IP address, requested URL, timestamp, referrer, browser, and device informationOperate, secure, and understand use of the Service

The public waitlist form submits an email address only. VibeReskin does not currently offer Google Sign-In or an application account, profile, or session. The private tool uses an HTTP Basic Auth gate at the reverse proxy.

2. How We Use Data and Legal Basis

Where GDPR or similar law applies, the legal basis depends on the activity and context. It may include:

3. Services and Network Providers

The exact services used depend on the operation and provider configuration. Data sent may include images, prompts, style instructions, filenames, and technical request metadata.

ServiceCurrent UseData That May Be Sent
Google GeminiImage generation, including the ImageGen toolPrompts, reference images, generation settings, and request metadata
OpenAIConfigured image-generation optionSource images, prompts, generation settings, and request metadata
Anthropic ClaudeAsset analysis, prompt generation, style wizard, and optional style critiqueUploaded images where analysis requires them, text prompts, style briefs, and request metadata
fal.aiBackground removal, upscaling, file transfer, and ByteDance Seedream processing when selectedImages, prompts, operation settings, and request metadata
Alibaba Cloud DashScope / QwenOptional fallback for analysis and prompt generation when configuredImages, prompts, and request metadata
analytics.vibereskin.comWebsite analytics script loaded by the landing, application, and legal pagesPage-view and related browser or request metadata
Google FontsFont delivery on the main website and applicationFont requests and associated network metadata
HetznerCurrent application-server hostingFiles and server records stored or transmitted through the hosted server

Each external provider handles data under its own terms, privacy policy, settings, and retention practices. Provider configuration can change, so contact us if you need the current provider used for a specific operation.

4. Data Storage & Security

The current application server is hosted with Hetzner in Finland. Uploaded assets, generated outputs, waitlist entries, job records, style data, and provider-cost records are stored in server files.

Current technical controls include:

No storage or transmission method can eliminate every security risk.

5. Data Retention

6. Your Rights and Choices

Depending on where you live and the law that applies, you may have rights to:

To make a request, email alexan.sitnikov@gmail.com. Include enough information to locate the relevant waitlist entry, file, or run. We may need to verify the request before acting on it. Rights and response periods vary by jurisdiction.

7. Cookies, Authentication, and Local Storage

The current VibeReskin frontend does not create an application account or set an application authentication/session cookie. Access to the private tool uses HTTP Basic Auth: your browser sends an Authorization header to the reverse proxy and may remember the credential according to browser behavior.

The frontend uses browser local storage for:

The frontend also uses session storage to remember an active generation job within the current browser tab.

The current frontend does not write uploaded image bytes to local storage. The Service also loads the analytics script described in Section 3. Its network requests and any browser storage it uses depend on the current analytics configuration and browser controls.

8. Children's Privacy

The Service is designed for professional game-asset workflows, not for children. Do not submit a child's personal data without any consent required by applicable law. If you believe a child has submitted personal data, contact us so we can review the request.

9. International Processing

The services listed in Section 3 may process data in countries outside your own. The location and transfer mechanism depend on the selected provider, its current infrastructure, and the law that applies. Review the relevant provider's privacy information before using an operation if cross-border processing is a concern.

10. Changes to This Policy

We may update this page when the Service, providers, or data flows change. The "Last updated" date at the top shows the date of this version. Material changes may also be posted on the Service.

11. Contact & Data Protection

For any privacy-related questions or to exercise your rights:

Oleksandr Sitnikov
Email: alexan.sitnikov@gmail.com
Location: Kyiv region, Ukraine

Where applicable, you may also be able to contact the data-protection or privacy authority in your jurisdiction.