Privacy policy
last updated 4 August 2026
This notice describes the data the current VibeSolid application actually uses. We do not sell personal data, run ads, use session replay, or send your content to an AI provider.
Controller and contact
VibeSolid is the controller for the account, gameplay, and certificate data described here. Contact: support@vibesolid.app.
Data we collect
- Account and authentication
Email address, encrypted password verifier, account and sign-in timestamps, authentication provider, and security records associated with sign-in. Supabase may process session IP address and user-agent data to authenticate sessions and investigate abuse. VibeSolid never receives your plaintext password.
- Profile and preferences
Your selected avatar and theme, plus a generic profile label. New accounts are not named from the email address.
- Gameplay and learning records
Scenario answers and run state, progress, scores, attempts, streak badges, checklist selections, quiz results and category scores, and certificate-exam results. Quiz results are linked by account ID; we do not store a second copy of your email with them.
- Public certificate
Only after you choose to issue one, the exact public name you enter, credential ID, and issue date are published on a verification page. The form identifies the public fields before publication. Deleting your account removes the registry record.
- Billing and orders
Plan, entitlement, Stripe customer/subscription/payment/session identifiers, checkout status, and billing-event timing. Card and bank details go directly to Stripe and do not reach VibeSolid servers.
- Security and hosting data
Requests reach Vercel, which may process IP address, request metadata, and operational logs. Abuse limits store pseudonymous keyed hashes and counters, not the raw address. Short-lived verification records are used for password reset and account deletion.
- Optional analytics
If you accept the equal-choice analytics prompt, Vercel Web Analytics receives page path, referrer, approximate country, device, browser, and operating-system information. Query strings are removed and account, sign-in, callback, and password-reset pages are excluded.
Why we use it and legal bases
- Contract
Create and secure your account, save learning progress, deliver paid features, process purchases, manage subscriptions, and issue a certificate when you request it.
- Legitimate interests
Prevent abuse and fraud, keep the service reliable, maintain minimal operational logs, enforce rate limits, and establish or defend legal claims. We limit this processing to what is necessary for those aims.
- Consent
Optional Web Analytics runs only after you accept it. You can reject initially or reopen “Analytics settings” in the footer and withdraw consent just as easily. Withdrawal does not affect earlier lawful processing.
- Legal obligation
Where applicable, retain the limited transaction records required for tax, accounting, refunds, disputes, or compliance.
Processors and other recipients
- Supabase
Authentication and PostgreSQL database hosting for account and product records.
- Stripe
Checkout, payments, subscriptions, refunds, and the customer billing portal. Stripe also retains payment records under its own legal duties.
- Vercel
Application hosting, firewall, function and operational logs, and — only with consent — Web Analytics.
- LinkedIn (user initiated)
Selecting “Add to LinkedIn” opens LinkedIn with the certificate name, issue date, credential ID, and public verification URL. Nothing is sent to LinkedIn unless you choose that action.
These providers may process data outside the UK or EEA. We rely on their published data-processing terms and applicable safeguards, such as UK or EU standard contractual clauses and adequacy mechanisms. Contact us for a copy or further information about the relevant safeguard.
Retention and deletion
- Account and product data
Kept while the account exists, then deleted from the live application database through the self-serve deletion control. User-owned database rows, including the public certificate, cascade from that deletion.
- Stripe
Account deletion cancels an active subscription and asks Stripe to delete the customer object. Stripe may retain transaction evidence it must keep for legal, tax, fraud, or dispute purposes under its own retention policy.
- Short-lived security data
Verification challenges expire after their stated short window. Rate limit buckets use windows no longer than 24 hours and expired buckets are removed during subsequent checks.
- Webhook replay ledger
Signed Stripe event IDs and event timing are retained for no more than 90 days, then removed by a daily database job. Webhook processing also performs the same cleanup as a fallback.
- Backups and logs
Deleted data may remain in access-restricted provider backups or security logs until overwritten under the provider's backup or log lifecycle. It is kept beyond ordinary use, is not restored except for disaster recovery, and any restored deletion is re-applied. Contact us for the current provider schedule that applies to a specific request.
Your rights
In your account, you can download a JSON copy of account, gameplay, certificate, and billing-reference data, or verify your email and delete the account.
Depending on the circumstances, you may also request access, rectification, erasure, restriction, portability, or object to processing based on legitimate interests. You may withdraw analytics consent in the footer. We normally respond within one month. You can complain to your supervisory authority; in the UK this is the Information Commissioner's Office (ICO). Email us for requests the self-serve controls do not cover.
Cookies and device storage
Essential Supabase authentication cookies keep you signed in. Theme, Patch Garden progress, some checklist state, and your analytics choice are stored locally in your browser. Optional Vercel Web Analytics is cookieless but remains off until you accept it. Rejecting analytics is as easy as accepting it and does not change product access.
Children and changes
VibeSolid is not directed at children under 16. Contact us if you believe a child created an account. Material notice changes will be shown here with a revised date and, where required, an additional notice or consent request.