Rib Creative
DocsCommunityPricing
Get Started
DocsCommunityPricing

Privacy Policy

Rib Creative collects and processes data needed to operate the AI-assisted builder, hosted apps, workspaces, exports, integrations, payments, support, security, and essential communications.

Data we collect and process

The data we process depends on how you use Rib Creative and which features you enable. We may process the following categories of data:

  • Account data, such as name, email, login method, profile details, authentication events, and settings.
  • Workspace data, such as members, invitations, roles, permissions, plan, billing status, and audit metadata.
  • Builder data, such as prompts, messages, instructions, attachments, screenshots, uploaded files, generated code, app copy, design assets, version history, build logs, project configuration, and agent activity.
  • Hosted runtime data, such as app configuration, environment variables, project secrets, auth users, database records, storage objects, emails, webhook events, exports, deployment metadata, and operational logs.
  • Usage and device data, such as IP-derived location, user agent, device type, pages viewed, referrer, workspace actions, feature usage, error events, performance data, and security signals.
  • Support and communications data, such as messages, attachments, issue details, and feedback.
  • Billing data, such as plan, invoices, payment status, credits, top-ups, usage records, and Stripe IDs.

Why we process data

We use data to authenticate users, operate workspaces, generate and modify projects, provide previews and hosted apps, process exports, run builds, connect integrations, provide support, send essential communications, measure usage, bill for services, detect abuse, secure the platform, debug errors, enforce terms, comply with law, and improve Rib Creative.

Legal bases

Where laws such as the GDPR or UK GDPR apply, Rib Creative relies on the legal bases that match the feature, role, and data involved. The same processing may also occur on documented customer instructions when Rib Creative acts as a processor or service provider.

ActivityTypical legal bases
Account, workspace, builder, hosting, support, billing, and security operations.Contract performance, legitimate interests, legal obligations, consent where required, and customer instructions for processor activity.
AI-assisted generation, debugging, and project analysis.Contract performance, legitimate interests in providing the requested feature, and customer instructions for customer-controlled project data.
Analytics, marketing measurement, and non-essential cookies.Legitimate interests where permitted and consent where required by applicable law or product settings.
Fraud prevention, abuse response, security monitoring, and legal compliance.Legitimate interests, legal obligations, vital interests where applicable, and establishment or defense of legal claims.

AI providers and generated projects

When you use AI-assisted features, prompts, messages, files, project context, generated code, screenshots, logs, and other relevant data may be sent to AI providers or model infrastructure so the platform can generate, edit, explain, test, or debug your project. AI providers may process that data under their own service terms, privacy terms, enterprise settings, retention rules, and safety policies.

Do not submit data to the builder unless you have the right to use it. Avoid entering passwords, private keys, production secrets, payment card numbers, health data, government identifiers, highly sensitive data, or regulated data unless you are authorized to do so and the feature is appropriate for that data.

Your projects, exports, and hosted apps

Rib Creative is designed to let users export projects and operate them outside the platform. While a project is hosted, previewed, built, or operated on Rib Creative infrastructure, we may process project files, runtime data, app logs, public URLs, assets, thumbnails, database data, storage data, auth data, and analytics needed to provide the service. Once you export or host a project outside Rib Creative, the hosting, telemetry, visitor data, secrets, databases, payments, and security controls are governed by your chosen providers and your app configuration.

If you publish an app, visitors and end users may submit data through forms, authentication, checkout, database-backed features, storage uploads, or other workflows you configure. You are responsible for giving your end users appropriate privacy notices and for using their data lawfully.

Integrations and OAuth

If you connect services such as GitHub, Google, Stripe, Supabase, email, storage, analytics, deployment, or other providers, Rib Creative may store and use tokens, scopes, account identifiers, repository metadata, file metadata, project metadata, database metadata, webhook events, and sync status needed to provide the integration. You can usually revoke third-party access through the provider or Rib Creative settings, though revocation may disable connected features.

Stripe and payments

If you configure Stripe for a project, Stripe may collect and process identity, business, tax, banking, risk, fraud, and compliance information through Stripe-hosted payment and account management surfaces. Rib Creative does not need to collect or store sensitive bank account details for user-app payment setup.

Rib Creative may receive and store operational payment metadata from Stripe, including account identifiers, account status, configured-secret metadata, payment status, refund or dispute indicators, webhook event identifiers, timestamps, and project or workspace metadata. We use this information to operate payment features, show connector status, respond to risk events, and support users.

Stripe may act as an independent controller or service provider for parts of payment processing, account management, risk review, compliance, and fraud prevention. Your use of Stripe is also subject to Stripe's privacy terms and applicable Stripe service terms.

Analytics, cookies, and operational logs

Analytics, cookies, local storage, and operational logging may apply to Rib Creative websites, dashboard surfaces, builder sessions, preview URLs, and apps hosted on Rib Creative domains or infrastructure. This may include page views, referrers, device information, coarse location, IP address, user agent, feature usage, errors, performance metrics, and security events. When you export or host content outside Rib Creative, visitor data and tracking are controlled by your chosen hosting provider, analytics tools, and app configuration.

Sharing and subprocessors

We may share data with service providers and Subprocessors that help us provide Rib Creative, including hosting, cloud infrastructure, AI model providers, payments, billing, email delivery, analytics, monitoring, storage, databases, customer support, security, and compliance providers. We may also disclose data when required by law, to protect the rights and safety of users or third parties, to investigate abuse, or as part of a business transaction such as a merger, acquisition, financing, or sale of assets.

Some providers are customer-controlled, such as a customer's own Stripe, GitHub, Supabase, analytics, deployment, or externally hosted app providers. Those providers process data under the customer's configuration and their own terms. See the Subprocessors page for current provider categories.

International processing

Rib Creative and its providers may process data in the United States, the EEA, the UK, Brazil, and other countries where users, providers, or infrastructure are located. Where required for EEA/UK personal data transfers, Rib Creative relies on adequacy decisions, Standard Contractual Clauses, the UK Addendum, or other lawful transfer mechanisms.

Retention by category

We keep data for as long as needed to provide the platform, maintain accounts and workspaces, operate hosted apps, comply with legal or financial obligations, resolve disputes, enforce terms, maintain security, and preserve backups. You may request account deletion or project deletion, and you may export supported project files from the platform. Some data may remain for a limited period in backups, logs, billing records, fraud prevention records, legal records, or third-party provider systems where retention is required or technically necessary.

CategoryTypical retention approach
Account and workspace recordsRetained while the account or workspace is active and for a limited period after deletion for security, dispute, backup, and legal needs.
Builder data and project filesRetained while the project is active, until deletion/export workflows complete, or while needed for support, backups, security, or legal obligations.
Hosted runtime dataRetained according to project configuration, database/storage lifecycle, backups, and customer deletion requests.
Usage, analytics, and logsRetained for diagnostics, abuse prevention, performance analysis, security, and incident response, usually for a limited operational period.
Billing, payment, tax, and fraud recordsRetained as required for invoices, tax, accounting, chargebacks, fraud prevention, compliance, and legal obligations.
Support and legal recordsRetained while needed to resolve requests, maintain business records, enforce terms, or comply with law.

Privacy rights

Depending on your location, you may have rights to access, correct, delete, export, restrict, or object to certain processing of your personal data. You may also have the right to withdraw consent where processing is based on consent. To make a request, contact us using the email below. We may need to verify your identity and workspace authority before fulfilling a request.

EEA/UK users may have rights to access, rectification, erasure, restriction, portability, objection, and to lodge a complaint with a supervisory authority. California users may have rights to know, delete, correct, limit certain sensitive personal information uses, opt out of certain sale or share activity, and avoid discrimination for exercising privacy rights. Rib Creative does not knowingly sell personal information for money, but some advertising or analytics activity may be considered a sale or share under certain state laws.

Minors

Rib Creative is not directed to children or minors under the age required by applicable law to use online services without parental or guardian consent. If you believe a child provided personal data through Rib Creative without appropriate consent, contact us so we can review the request.

Security

We use technical and organizational measures designed to protect data, but no online service can guarantee absolute security. You are responsible for configuring your projects, exports, secrets, access controls, integrations, and end-user workflows securely.

Controller contact

Rib Creative is the controller for platform account, billing, security, support, and website data where it decides the purposes and means of processing. For customer app data, Rib Creative usually acts as a processor or service provider. Questions, deletion requests, or privacy rights requests can be sent to support@ribcreative.com.

Questions or deletion requests? Email support@ribcreative.com.

Rib Creative

Create custom apps and websites by chatting with AI.

Company

  • Home
  • Contact
  • Security

Product

  • Start building
  • Pricing
  • Payments

Resources

  • Learn
  • Legal Center
  • Cookies
  • Subprocessors

Legal

  • Terms
  • Privacy
  • Acceptable Use
  • DPA
  • Copyright

Community

  • Discord
  • Reddit
  • Instagram

© 2026 Rib Creative Lab - All rights reserved.