legal

Privacy Policy

Last updated July 17, 2026

This Privacy Policy explains how Dibs AI Inc., a Delaware C Corporation ("Dibs", "we", "us"), collects, uses, and shares information when you use the Dibs platform at dibslabs.com and related sites, applications, and integrations (the "Service"). By creating an account or using the Service, you agree to this Policy.

01Who we are

Dibs AI Inc. is a Delaware C Corporation that operates Dibs, an AI studio for short-form social content. We are the controller of the personal information described in this Policy. You can reach us using the details in the "Contact" section below.

02Scope

This Policy applies to:

  • our website and web application at dibslabs.com and related domains;
  • third-party accounts and platforms you choose to connect to the Service (such as TikTok or Instagram) via OAuth; and
  • any other digital property that links to this Policy.

03Information we collect

  • Account & team data. Your name, email, password (stored hashed), and the teams you belong to, including roles and invitations.
  • Content & inputs. Prompts, source links and articles, personas, content ideas, briefs, captions, and other inputs you submit for AI generation, together with the media and text the Service generates from them. This includes reference images and likeness you upload to train a persona "identity" (a reusable persona identity).
  • Connected-account data. When you connect a third-party platform (such as TikTok or Instagram), we receive and store an OAuth access token and, where the platform issues one, a refresh token (encrypted at rest), the connected account's identifiers, display name, username, avatar, and basic profile and statistics (such as follower, following, like, and post counts), to the extent the platform's scopes you authorize provide them. For content you publish through the Service, we also retrieve that post's performance metrics (such as views, likes, comments, and shares) so we can show them to you.
  • Billing data. Subscription, seat, and token-purchase records, and your token usage ledger. Card details are handled by our payment processor (Stripe) — we do not store full card numbers.
  • Usage, device & activity-log data. Log data, IP address, browser/user-agent, the URLs you access, and a record of meaningful actions taken in the Service (including before/after changes), which we keep in an audit log for security, compliance, and abuse prevention.
  • Cookies & analytics. Strictly necessary cookies for authentication and session management, first-party analytics cookies set by Google Analytics to measure aggregate, non-advertising usage of the Service, and — with your consent or until you opt out — marketing cookies for website-visitor identification (see "Cookies & tracking").
  • Website-visitor data. On our public homepage we use a third-party visitor-identification provider (RB2B, operated by Retention.com) that may resolve an anonymous business visitor to a professional identity — such as a name, work email, professional (e.g. LinkedIn) profile, and employer — and sets related first-party cookies, including a persistent visitor identifier. This runs only on our public homepage (not on our app, legal, privacy, or Do-Not-Sell pages), only in the United States and similar opt-out regions until you opt out — it does not run in the EU/UK — and never for signed-in users. You can opt out at any time (see "Cookies & tracking" and "Your rights").

04How we collect information

We collect information:

  • directly from you when you create an account, configure teams, submit inputs, or contact us;
  • automatically as you use the Service, through logs, cookies, and our audit trail; and
  • from third parties you connect or point us to — for example, profile and statistics from a social platform you authorize via OAuth, or the contents of RSS feeds and article URLs you add as sources, which we fetch on your behalf.

05How we use information

  • To provide, operate, secure, and improve the Service.
  • To generate the content you request via our third-party AI providers.
  • To publish, schedule, or manage content on platforms you connect, when you instruct us to (including posts you schedule for a future time).
  • To process subscriptions, seats, token purchases, and grants, and to meter usage.
  • To secure the Service, prevent abuse, and maintain our audit log.
  • To develop and improve our Service and systems, including AI features (see "AI processing & model training").
  • To communicate with you about your account and the Service.

06AI processing & model training

The Service uses artificial intelligence to process your inputs and produce the outputs you request. We use the data you submit to operate, develop, and improve the Service and our systems.

  • Persona "identity". When you train an identity, we use the reference images you provide to create a private, per-persona likeness model that is used to generate that persona's media for your team.
  • Model training. We do not use your reference images, persona likeness, or any biometric data to train, fine-tune, or improve any model other than your own private, per-persona identity, and we never use them to train shared or general-purpose models. Any other content you submit is used to improve the Service only in de-identified or aggregated form that does not identify you.
  • Third-party AI providers. To generate content, we share the minimum necessary inputs with third-party AI providers that perform text generation and image/video generation on our behalf. They process those inputs under their own terms to return outputs to us.

AI output may be inaccurate, may resemble other outputs, and is not guaranteed to be unique or fit for any purpose. You are responsible for reviewing output before you use it.

07Biometric & likeness data

When you create a persona, you may upload reference images (and, where offered, voice characteristics) of a real person, which we use to build a private, per-persona "identity" that lets the Service generate images and video of that persona. To the extent these reference images, the identity model, or any derived templates constitute "biometric identifiers" or "biometric information" under laws such as the Illinois Biometric Information Privacy Act (BIPA), the Texas CUBI Act, or Washington law — or "sensitive personal information" under the CCPA/CPRA or "special category data" under the GDPR — we handle them as follows:

  • Purpose & basis. We use them only to create and operate the persona you direct us to build — never to identify members of the public, and never for advertising. Where consent is required (including under the GDPR), we rely on the explicit consent you and the depicted person provide (see our Terms of Use).
  • No sale or profit. We do not sell, lease, trade, or otherwise profit from biometric or likeness data.
  • Retention & destruction. We retain the reference images and identity model for as long as the persona exists, and destroy them when you delete the persona or your account, or within three years of your last interaction with that persona, whichever comes first.
  • Your controls. You can delete a persona — and its identity model and reference images — at any time in the Service. Where applicable, you may also direct us to limit our use of sensitive personal information and exercise the other rights in "Your rights".

If a persona depicts you. A persona may be built from the likeness of someone other than the account holder. If a persona depicts you and you did not create it, you have rights over your personal information regardless of who holds the account. To request access to, or deletion of, a likeness model and reference images that depict you, contact us at legal@dibslabs.com with enough detail to identify the persona; we act on verified requests as required by applicable law. We rely on the account holder's representation that they obtained the consents and releases required (see our Terms of Use), and we do not independently onboard or verify the depicted person.

08Service providers & subprocessors

To deliver the Service we share the minimum necessary data with providers who act on our behalf:

  • AI providers — a third-party text generation provider and a third-party image and video generation provider (the latter also trains the persona identity). Your prompts, source text, and reference images are sent to them to produce output.
  • Stripe — payment processing and billing, under its own privacy policy.
  • TikTok — when you connect a TikTok account and ask us to publish, we send the relevant media and captions to TikTok on your behalf.
  • Meta Platforms, Inc. (Instagram) — when you connect an Instagram professional account and ask us to publish, we send the relevant media and captions to Instagram on your behalf, and we retrieve the profile information and post metrics described in "Information we collect" through Instagram's API.
  • Cloud hosting, storage & messaging — the infrastructure providers that host the application and database (Laravel Cloud, operated on Amazon Web Services), deliver traffic and store media (Cloudflare), send email, and deliver real-time updates.
  • Google Analytics — aggregate product analytics. We run it with Google Signals and ad personalization disabled, so it is not used for cross-context behavioral advertising.
  • RB2B (Retention.com) — website-visitor identification on our public homepage (United States and similar opt-out regions only). Where it runs, an anonymous business visit may be resolved to a professional identity (name, work email, professional profile, and employer) as described in "Information we collect".

Other than the website-visitor identification described here and in "Cookies & tracking", we do not sell your personal information or share it for cross-context behavioral advertising. Under the CCPA/CPRA, that visitor identification may be considered a "sale" or "sharing" of personal information. You can opt out at any time — see "Your rights" and our Do Not Sell or Share My Personal Information page.

09Connected social accounts

Connecting a platform such as TikTok or Instagram is optional. When you do, you grant the Service the access scopes shown during the connection flow, and we store the resulting OAuth tokens encrypted at rest. We use them only to read your basic profile and statistics and to publish or manage content at your direction. You can disconnect an account at any time, in the Service or in the platform's own settings; on disconnect we delete the stored connection, including the tokens, the imported profile information, and the post metrics we retrieved for it. Your use of each platform remains subject to that platform's terms and privacy policy.

For Instagram, the same deletion also happens automatically from the platform side: if you remove the Service from your Instagram account's connected apps, or submit a data deletion request to Meta, Meta notifies us and we immediately delete the stored connection and all data we received from Instagram for that account, and provide Meta a confirmation code and status page for the deletion. You can also email us at any time (see "Contact") to request the same deletion.

10Sharing & disclosure

We share information only with the service providers above, with your team members as inherent in a shared workspace, when required by law or to protect our rights, or in connection with a merger, acquisition, or financing.

11Cookies & tracking

We use strictly necessary cookies to authenticate you and maintain your session. We also use Google Analytics 4, which sets first-party analytics cookies and collects limited usage data — the pages you view, approximate location derived from your IP address, device and browser information, and in-app navigation events — so we can understand aggregate usage and improve the Service. We run Google Analytics with Google Signals and ad personalization disabled, so this data is not used for cross-context behavioral advertising or interest-based profiling, and we do not use your generated content or connected social-account data for advertising. You can opt out using your browser's controls or Google's opt-out tools, and we honor a Global Privacy Control signal.

On our public homepage we also use a website-visitor identification provider (RB2B, operated by Retention.com), which sets first-party cookies — including a persistent visitor identifier (up to ~360 days) — to recognize anonymous business visitors. We load it behind a consent gate: it runs only in the United States and similar opt-out regions until you opt out, does not run in the EU/UK, never runs for signed-in users, and we always honor a Global Privacy Control signal. You can change your choice at any time using the cookie banner, the "Manage cookie preferences" control below, or our Do Not Sell or Share page, or directly with the provider at app.retention.com/optout (US) or rb2b.com/rb2b-gdpr-opt-out (EU/UK).

The cookies and similar technologies we use fall into three categories. Strictly necessary cookies always run; analytics and marketing cookies run only with your consent (in the EU/UK) or until you opt out (in the US), and we always honor a Global Privacy Control signal.

You can change your analytics and marketing choices at any time. This updates the dibs_consent cookie on this device; turning a category off immediately stops the related scripts (we reload the page to clear them) and prevents them loading on future page views.

12Data retention

We retain your account and content for as long as your account is active. Audit-log entries are retained for a limited period (by default, 365 days) and then pruned. Billing and token-ledger records are retained as required for tax, accounting, and audit purposes. Connected social account data — OAuth tokens, imported profile information, and post metrics — is retained only while the account remains connected and is deleted when you disconnect it (or, for Instagram, when Meta notifies us that you removed the Service or requested deletion). You may request deletion as described below; some records may be retained where required by law.

Tracking data follows its own schedules: analytics data is retained per our Google Analytics configuration (the _ga / _ga_* cookies expire after about 24 months), and any website-visitor-identification records are retained per our provider's (Retention.com) terms — separate from the up-to-360-day lifetime of the first-party identifier cookie set on your device, which you can clear at any time. Reference images and persona likeness models follow the schedule in "Biometric & likeness data".

13Security

We use industry-standard measures to protect your data, including encryption in transit and encryption of stored OAuth tokens. If we discover a security incident affecting your personal data, we will notify affected users and any relevant platform partners without undue delay, consistent with applicable law. No method of transmission or storage is perfectly secure, and we cannot guarantee absolute security.

14Your rights

Depending on where you live (including under the EU/UK GDPR, the California CCPA/CPRA, and the comprehensive privacy laws of states such as Virginia, Colorado, Connecticut, Texas, and Oregon), you may have the right to access, correct, export, or delete your personal information; to object to or restrict certain processing; and to opt out of targeted advertising, the sale or sharing of your information, and certain profiling. You may also designate an authorized agent to make a request on your behalf. To exercise these rights, contact us at legal@dibslabs.com.

We will not discriminate against you for exercising your privacy rights. Where you have provided sensitive personal information, you may direct us to limit its use. If we rely on your consent for a processing activity, you may withdraw that consent at any time, without affecting processing already carried out. If you are in the EU/UK, you also have the right to lodge a complaint with your local data-protection supervisory authority.

You also have the right to opt out of the "sale" or "sharing" of your personal information through our website-visitor identification. You can exercise it on our Do Not Sell or Share My Personal Information page, via the cookie banner or the "Manage cookie preferences" control in "Cookies & tracking", or by sending a Global Privacy Control signal, which we honor automatically.

If a persona depicts you and you did not create it, see "Biometric & likeness data" for how to request access to or deletion of your likeness.

15International transfers

We are based in the United States and process data there. If you access the Service from outside the U.S., you consent to transferring your information to the U.S. and the jurisdictions of our service providers, including providers such as Google (for analytics) that may process data in the U.S. and elsewhere.

16Children

The Service is not directed to children under 16, and we do not knowingly collect their information.

17Changes

We may update this Policy from time to time. We will revise the "last updated" date and, for material changes, provide additional notice.

18Contact

For general questions, email hello@dibslabs.com. For privacy requests or other legal matters, email legal@dibslabs.com. You can also call +1 (415) 915-2747, or write to us at:

Dibs AI Inc.
2261 Market Street STE 85799
San Francisco, CA 94114
USA