This Privacy Policy explains how Dibs AI Inc., a Delaware C Corporation ("Dibs", "we", "us"), collects, uses, and shares information when you use the Dibs platform at dibslabs.com and related sites, applications, and integrations (the "Service"). By creating an account or using the Service, you agree to this Policy.
Dibs AI Inc. is a Delaware C Corporation that operates Dibs, an AI studio for short-form social content. We are the controller of the personal information described in this Policy. You can reach us using the details in the "Contact" section below.
This Policy applies to:
We collect information:
The Service uses artificial intelligence to process your inputs and produce the outputs you request. We use the data you submit to operate, develop, and improve the Service and our systems.
AI output may be inaccurate, may resemble other outputs, and is not guaranteed to be unique or fit for any purpose. You are responsible for reviewing output before you use it.
When you create a persona, you may upload reference images (and, where offered, voice characteristics) of a real person, which we use to build a private, per-persona "identity" that lets the Service generate images and video of that persona. To the extent these reference images, the identity model, or any derived templates constitute "biometric identifiers" or "biometric information" under laws such as the Illinois Biometric Information Privacy Act (BIPA), the Texas CUBI Act, or Washington law — or "sensitive personal information" under the CCPA/CPRA or "special category data" under the GDPR — we handle them as follows:
If a persona depicts you. A persona may be built from the likeness of someone other than the account holder. If a persona depicts you and you did not create it, you have rights over your personal information regardless of who holds the account. To request access to, or deletion of, a likeness model and reference images that depict you, contact us at legal@dibslabs.com with enough detail to identify the persona; we act on verified requests as required by applicable law. We rely on the account holder's representation that they obtained the consents and releases required (see our Terms of Use), and we do not independently onboard or verify the depicted person.
To deliver the Service we share the minimum necessary data with providers who act on our behalf:
Other than the website-visitor identification described here and in "Cookies & tracking", we do not sell your personal information or share it for cross-context behavioral advertising. Under the CCPA/CPRA, that visitor identification may be considered a "sale" or "sharing" of personal information. You can opt out at any time — see "Your rights" and our Do Not Sell or Share My Personal Information page.
Connecting a platform such as TikTok or Instagram is optional. When you do, you grant the Service the access scopes shown during the connection flow, and we store the resulting OAuth tokens encrypted at rest. We use them only to read your basic profile and statistics and to publish or manage content at your direction. You can disconnect an account at any time, in the Service or in the platform's own settings; on disconnect we delete the stored connection, including the tokens, the imported profile information, and the post metrics we retrieved for it. Your use of each platform remains subject to that platform's terms and privacy policy.
For Instagram, the same deletion also happens automatically from the platform side: if you remove the Service from your Instagram account's connected apps, or submit a data deletion request to Meta, Meta notifies us and we immediately delete the stored connection and all data we received from Instagram for that account, and provide Meta a confirmation code and status page for the deletion. You can also email us at any time (see "Contact") to request the same deletion.
We share information only with the service providers above, with your team members as inherent in a shared workspace, when required by law or to protect our rights, or in connection with a merger, acquisition, or financing.
We use strictly necessary cookies to authenticate you and maintain your session. We also use Google Analytics 4, which sets first-party analytics cookies and collects limited usage data — the pages you view, approximate location derived from your IP address, device and browser information, and in-app navigation events — so we can understand aggregate usage and improve the Service. We run Google Analytics with Google Signals and ad personalization disabled, so this data is not used for cross-context behavioral advertising or interest-based profiling, and we do not use your generated content or connected social-account data for advertising. You can opt out using your browser's controls or Google's opt-out tools, and we honor a Global Privacy Control signal.
On our public homepage we also use a website-visitor identification provider (RB2B, operated by Retention.com), which sets first-party cookies — including a persistent visitor identifier (up to ~360 days) — to recognize anonymous business visitors. We load it behind a consent gate: it runs only in the United States and similar opt-out regions until you opt out, does not run in the EU/UK, never runs for signed-in users, and we always honor a Global Privacy Control signal. You can change your choice at any time using the cookie banner, the "Manage cookie preferences" control below, or our Do Not Sell or Share page, or directly with the provider at app.retention.com/optout (US) or rb2b.com/rb2b-gdpr-opt-out (EU/UK).
The cookies and similar technologies we use fall into three categories. Strictly necessary cookies always run; analytics and marketing cookies run only with your consent (in the EU/UK) or until you opt out (in the US), and we always honor a Global Privacy Control signal.
You can change your analytics and marketing choices at any time. This updates the dibs_consent cookie on this device; turning a category off immediately stops the related scripts (we reload the page to clear them) and prevents them loading on future page views.
We retain your account and content for as long as your account is active. Audit-log entries are retained for a limited period (by default, 365 days) and then pruned. Billing and token-ledger records are retained as required for tax, accounting, and audit purposes. Connected social account data — OAuth tokens, imported profile information, and post metrics — is retained only while the account remains connected and is deleted when you disconnect it (or, for Instagram, when Meta notifies us that you removed the Service or requested deletion). You may request deletion as described below; some records may be retained where required by law.
Tracking data follows its own schedules: analytics data is retained per our Google Analytics configuration (the _ga / _ga_* cookies expire after about 24 months), and any website-visitor-identification records are retained per our provider's (Retention.com) terms — separate from the up-to-360-day lifetime of the first-party identifier cookie set on your device, which you can clear at any time. Reference images and persona likeness models follow the schedule in "Biometric & likeness data".
We use industry-standard measures to protect your data, including encryption in transit and encryption of stored OAuth tokens. If we discover a security incident affecting your personal data, we will notify affected users and any relevant platform partners without undue delay, consistent with applicable law. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.
Depending on where you live (including under the EU/UK GDPR, the California CCPA/CPRA, and the comprehensive privacy laws of states such as Virginia, Colorado, Connecticut, Texas, and Oregon), you may have the right to access, correct, export, or delete your personal information; to object to or restrict certain processing; and to opt out of targeted advertising, the sale or sharing of your information, and certain profiling. You may also designate an authorized agent to make a request on your behalf. To exercise these rights, contact us at legal@dibslabs.com.
We will not discriminate against you for exercising your privacy rights. Where you have provided sensitive personal information, you may direct us to limit its use. If we rely on your consent for a processing activity, you may withdraw that consent at any time, without affecting processing already carried out. If you are in the EU/UK, you also have the right to lodge a complaint with your local data-protection supervisory authority.
You also have the right to opt out of the "sale" or "sharing" of your personal information through our website-visitor identification. You can exercise it on our Do Not Sell or Share My Personal Information page, via the cookie banner or the "Manage cookie preferences" control in "Cookies & tracking", or by sending a Global Privacy Control signal, which we honor automatically.
If a persona depicts you and you did not create it, see "Biometric & likeness data" for how to request access to or deletion of your likeness.
We are based in the United States and process data there. If you access the Service from outside the U.S., you consent to transferring your information to the U.S. and the jurisdictions of our service providers, including providers such as Google (for analytics) that may process data in the U.S. and elsewhere.
The Service is not directed to children under 16, and we do not knowingly collect their information.
We may update this Policy from time to time. We will revise the "last updated" date and, for material changes, provide additional notice.
For general questions, email hello@dibslabs.com. For privacy requests or other legal matters, email legal@dibslabs.com. You can also call +1 (415) 915-2747, or write to us at:
Dibs AI Inc.
2261 Market Street STE 85799
San Francisco, CA 94114
USA