1. Account workspace
The signed-in account workspace has five destinations. It uses current-viewer data and does not inherit a creator Stage theme. This Help article is public documentation and does not read or change your account.
| Destination | Current purpose |
|---|---|
| Overview | Current account identity and links to Profile, Security, Subscriptions, and Notifications |
| Profile | Personal name, username, date of birth, bio, email display, and eligible profile-image editing |
| Security | Password change, optional passkeys, email-verification status, and email OTP step-up explanation |
| Subscriptions | Audience memberships and separate Stage-admin access, including supported cancellation actions |
| Notifications | A paginated in-app inbox with All and Unread views, read state, and safe internal destinations |
2. Profile & visibility
Profile controls your global account identity. A Stage member-directory profile is a separate Stage-specific record with its own opt-in visibility setting; there is no one global public/private switch.
| Field | Edit boundary | Visibility boundary |
|---|---|---|
| First and last name | Up to 30 characters each | May appear in the limited public user projection and author surfaces |
| Username | Unique; 3–30 characters; starts with a letter | May appear with authored content and interactions |
| Date of birth | Required for a completed profile | Not included in the public user projection |
| Bio | Optional; up to 1,024 characters | Not included in the global public user projection |
| Visible in Profile but not editable there | Not included in the public user projection | |
| Profile image | URL-backed; upload needs an account that manages a Stage | May appear in the public user projection and author surfaces |
3. Account security
| Surface | Current behavior | Boundary |
|---|---|---|
| Password | Current password plus a new 8–256-character value using at least two character categories | A successful change revokes existing sessions and issues one fresh password session to the current browser; three changes per hour |
| Passkeys | Optional WebAuthn credentials that you can add, list, and remove | Password sign-in remains available; there is no passkey rename, recovery-code, SMS, authenticator-app, or session-management screen |
| Email verification & OTP | Verification links expire after 24 hours; a separate short-lived six-digit code can confirm guarded sensitive creator/admin actions | The code is not an every-login challenge or a general audience 2FA preference |
Security messages support specific flows such as verification, password reset, and guarded-action codes. The current product does not promise an alert for every suspicious login or account change.
4. Notifications & email
The in-app inbox and creator newsletter email are different systems. Unsubscribing from one Stage newsletter does not delete an in-app notification, cancel a Stage membership, or disable account security messages.
| Surface | Implemented behavior | Current limit |
|---|---|---|
| In-app notifications | 20 newest-first items per page; All and Unread views; open-to-mark-read; Mark all read; Load more | No delete, archive, search, type filter, notification preferences, push settings, or read-to-unread action |
| Creator newsletter email | Stage-specific confirmation and unsubscribe links manage that newsletter subscription | Separate from in-app notifications and Stage membership; no central email-preference or product-marketing settings page |
5. Subscriptions & payments
Account Subscriptions separates audience memberships from Stage-admin access. Audience rows can show the Stage, current plan, status, configured prices, benefits, and access-until date when available. Free cancellation removes access immediately; paid cancellation schedules the membership to end at the current paid period boundary.
Stripe-hosted checkout collects card or payment details. Vibeler processes provider identifiers, transaction status, amount and currency, and records needed for access and accounting, but the audience account currently has no card summary, saved payment-method manager, billing portal, invoice or receipt list, plan-change flow, retry, audience self-serve refund request, resubscribe, cancellation undo, or admin self-leave action. Account Subscriptions does include payment-history rows for memberships, purchases, courses, tips, refunds, and disputes.
6. Information processed
Vibeler processes more than the fields shown in Profile. The current application and operating policies cover the categories below when the related feature is used.
| Category | Examples |
|---|---|
| Account & authentication | Profile fields, email-verification state, session and security records, and passkey metadata where used |
| Stage relationships | Audience memberships, channel entitlements, Stage-admin access, and ban/access state |
| Content & community | Created content, comments and reactions, community profiles, events and RSVPs, and course progress where used |
| Commerce | Provider identifiers, checkout/subscription/payment status, amount and currency, purchases, and tips where used |
| Communications | In-app notifications plus newsletter confirmation and unsubscribe state |
| Technical & analytics | Random anonymous browser ID or authenticated user ID, timestamps, referrer, user agent, request IP/logs, approximate network location, and implemented view/listen/watch duration |
7. Cookies & analytics
- Authentication
- A same-origin HttpOnly session cookie supports signed-in access.
- Analytics identity
- An authenticated event can use the user ID. Anonymous analytics use a random browser ID stored in local storage rather than an ID derived from browser characteristics.
- Other local storage
- Creator upload workflows can retain resumable-upload state on the device. Selected features can also route through Stripe or load a creator-selected third-party embed.
The current implementation does not use advertising profiles or cross-site ad pixels, but the broader technical and policy record does not support absolute claims that Vibeler never tracks, never processes location, or uses only aggregate anonymous analytics. Approximate network-derived location and authenticated analytics can be processed where described above.
Read the current Cookie Policy for the operating cookie and storage description.
8. Privacy requests & current limits
The current Privacy Policy describes access, correction, and deletion requests subject to identity verification, applicable law, and legal or operational limits. These requests are handled through the published privacy contact rather than a self-serve account workflow.
Retention varies by data type and purpose, including operation, backups, payment and accounting records, legal compliance, disputes, security, fraud prevention, and enforcement. Raw analytics have a scheduled 730-day cleanup path; that is not a universal retention period for every category. The implementation does not guarantee automatic comment anonymization or universal seven-year retention after account deletion.
- No self-service data download or export
- No self-service account deletion, request status, cancellation, restoration, or data-inventory screen
- No cookie-consent manager in the current product
- No universal avatar upload for an audience-only account
- No email-address edit in Profile
- No account-wide email, marketing, push, or notification preference center
- No saved cards, payment-method manager, invoices, receipts, audience self-serve refund request, or dispute workflow in the audience account
Signup collects a date of birth but does not currently enforce one universal age threshold in the profile schema. The Terms say Vibeler is not directed to children and require parent or guardian involvement where applicable law requires consent.
9. Read next
Use the payment guide for membership and checkout behavior, and the current policy pages for privacy or legal interpretation.