Privacy Policy
Last updated: August 25, 2026
Summary
VibeVersity, Inc. ("VibeVersity," "we," "us," or "our") collects the minimum personal data we need to run your account, deliver courses, and keep the service reliable and safe. We do not sell your personal data. We do not share it for cross-context behavioral advertising. We honor Global Privacy Control (GPC) signals as opt-outs. For any privacy question or to exercise a privacy right, contact our privacy team.
Who we are
VibeVersity, Inc. is a Delaware corporation that provides an AI-training platform at vibeversity.com. The data controller for personal data we collect is VibeVersity, Inc. The “VibeVersity” name and mark are owned by Seeking Sunrise, LLC, a Delaware limited liability company, and used by VibeVersity, Inc. under license; this licensing arrangement does not affect how your personal data is handled. For GDPR purposes we do not have an EU establishment; EU/UK users may contact our privacy team.
What we collect and why
We collect only the categories described below, for the purposes listed.
- Account data — email, name (optional), password hash (handled by our authentication provider). Used to create and secure your account. Legal basis (EU/UK): contract performance.
- Billing data — billing address, tax status, and payment card details (tokenized by our PCI-DSS-compliant payment processor; we never see the raw card number). Used to charge your subscription and issue receipts. Legal basis: contract performance + legal obligation (tax, fraud).
- Course data — lessons you've started, exercise submissions, grades, completion timestamps. Used to deliver and improve the curriculum. Legal basis: contract performance.
- Usage data (optional) — page views, routes, referrers, coarse geolocation and device/browser categories, general usage, and purchase-completion events captured by our analytics providers when you opt in. Used to understand what works and improve the product. Our cookie-less hosting analytics receives path-only page URLs and no custom events or account identifiers. Our currently active traffic and hosting analytics do not receive account identifiers. With your consent, we may also collect sampled, masked session replay for product improvement and error diagnosis. Replay is configured to mask text, inputs, and media. Optional analytics and replay are currently disabled for visitors in the EEA and United Kingdom while our territorial-scope and ePrivacy review is incomplete. Where optional analytics is available, you can withdraw consent at any time from the cookie preferences below.
- Error and security data (essential) — error payloads captured by our error-monitoring provider, and the ordinary technical data described under Security telemetry. Legal basis: legitimate interests (keeping the service running, secure, and debuggable).
- Security telemetry — IP address (truncated and salted-hashed for rate-limit and abuse detection), request headers, bot-protection challenge tokens. Legal basis: legitimate interests (security and fraud prevention). Like any website, our hosting and security systems process ordinary technical request data — IP address, browser and device information, the page requested, the response status, and a timestamp — to keep the service available and to detect abuse.
- Communications — emails you send us and replies from us, retained for 2 years for continuity and dispute resolution. Legal basis: legitimate interests.
When you complete a purchase we record that a purchase completed, its value, its currency, and which plan it was for. We do not include card or bank details, transaction or order identifiers, or your account identifier in these traffic and purchase-completion events.
How we use AI on your data
We do not train third-party AI models on your submitted exercises, code, or messages. Submitted content is not shared with model providers for training purposes. When we process your content with a model vendor (e.g. to grade an exercise), we use vendor APIs with training opt-out enabled and retention configured to the minimum offered by that vendor. If this changes, we will update this policy and notify active customers at least 14 days before the change takes effect.
Categories of recipients (sub-processors)
We share personal data only with the categories of service providers below, each acting under contract on our instructions (our "sub-processors"). We name our product-analytics provider because its retention limitation is material; other infrastructure is described by function. A current named list is available to you on request — just contact us. We review this list at least annually and update it before a new category of recipient goes live.
| Category of recipient | Purpose |
|---|---|
| Payment processing | Subscription billing, payments, and the customer billing portal |
| Authentication & identity | Account sign-in, session management, and account recovery |
| Application hosting & database | Running the platform and storing your account, course progress, and submissions |
| Cloud infrastructure | Underlying compute and storage |
| Content delivery & bot protection | Edge delivery and abuse/bot prevention on forms |
| Rate limiting & abuse prevention | Request throttling and idempotency |
| Email & SMS messaging | Transactional email and text-message notifications you have asked for |
| PostHog, Inc. — product analytics | Consent-gated product usage under the provider-managed retention described below |
| Error monitoring | Essential crash diagnosis and consent-gated performance or masked diagnostic replay |
International transfers
VibeVersity is operated from the United States. If you access the Services from outside the United States, your information will be transferred to, stored, and processed in the United States. Personal data of EU/UK users is transferred under the EU Standard Contractual Clauses (and the UK Addendum) built into our vendor agreements. To request a copy of the clauses, contact our privacy team.
Your rights
Everyone can:
- Access a copy of the data we hold about you.
- Correct inaccurate data.
- Delete your data (subject to narrow exceptions for legal, accounting, and fraud-prevention records we must retain).
- Export your data in a portable format.
- Object to, or restrict, specific processing activities.
- Withdraw consent (where we rely on consent).
California residents: where the CCPA applies, it provides rights to know the categories we collect, delete, correct, and opt out of sale or sharing. VibeVersity is currently below the CCPA's business thresholds, but we voluntarily accept the requests listed above. VibeVersity does not sell personal information and does not share it for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA, so there is nothing to opt out of — but you may still submit a request and we will record your preference. We honor GPC signals as an opt-out. We will not discriminate against you for exercising any of these rights.
EU/UK residents have the rights listed above under the GDPR and UK GDPR, plus the right to lodge a complaint with your local supervisory authority.
To exercise any right, contact our privacy team. We may need to verify your identity before processing access, correction, deletion, or portability requests. Opt-out requests do not require identity verification beyond a working email address. For EU/UK requests, we respond without undue delay and within one month, with a permitted extension communicated within that first month. For California requests, we acknowledge receipt within 10 business days and respond within 45 calendar days (extendable once by 45 days with notice; opt-out: within 15 business days). We never charge a fee unless a request is manifestly unfounded or excessive. You may designate an authorized agent to make a request on your behalf, subject to verification.
Account deletion
Signed-in users can initiate permanent deletion directly from the account page. If an account has a recurring subscription, renewal must first be canceled in the Stripe-hosted billing portal; deletion can proceed immediately once cancellation is scheduled. Deletion removes the shared VibeVersity login and initiates erasure of associated product data. Billing, tax, fraud-prevention, and audit records are retained only where required or permitted by law and under the retention periods below.
Cookies and tracking
We use a small set of first-party cookies required to keep you signed in, persist your theme, and remember your consent preferences. Optional analytics technologies and session replay are off by default and only enabled if you opt in via the cookie banner. We ask again after 180 days. An expired or future-dated choice returns to pending, with optional analytics off until you make a new choice. We also ask again before materially expanding the purposes, recipients, data categories, identification, replay capabilities, or retention covered by your analytics choice. If you consent, we may collect sampled, masked session replay for the analytics, product-improvement, and diagnostic purposes stated above. Text, inputs, and media are masked. This includes both cookie-based and cookie-less analytics. We honor the Sec-GPC Global Privacy Control header as an opt-out of analytics and any future sale or sharing.
Optional analytics and session replay are disabled for visitors in the EEA and United Kingdom even if an earlier analytics preference says “Accept.” Our hosting boundary derives a country code from the request and stores only a coarse first-party restricted or standard marker for up to 24 hours; the country itself is not stored in this cookie. A missing or invalid location signal on the production site fails closed and keeps optional analytics disabled. This necessary marker exists only to enforce the regional restriction.
If you opt in to analytics, our cookie-less hosting analytics measures page views, routes, referrers, coarse geolocation derived from the request, and device, browser, and operating-system categories. Before transmission we reduce each page URL to its same-origin path, excluding query strings and fragments. The provider uses a short-lived hash derived from the incoming request for aggregate visitor and session counts; it is discarded after 24 hours and is not reusable across other sites or applications. We do not send custom events or account identifiers to that service. If you opt in, our hosting provider also measures field performance metrics such as page loading, responsiveness, and layout stability. Your analytics choice applies site-wide rather than page by page. When analytics is enabled, performance measurement remains active on public, private, and unrecognized pages. These measurements include network speed, coarse country, browser, device type, and operating system. The browser library may generate an element attribution selector used to identify the page element involved in a Web Vital; our same-origin intake removes that selector and does not retain or forward it to the hosting provider. Before provider transmission, we replace public dynamic paths with a reviewed route template, collapse account, board, assessment, checkout, authentication, and onboarding pages into coarse route-family labels, and report any unrecognized page only as /other. We remove the concrete page URL, query string, fragment, and path identifiers; we do not associate these data points with an account or use them to reconstruct a browsing session across pages. A separate traffic-analytics service sets first-party cookies on this site to measure page views, general usage, and completed purchases. We do not include card or bank details, transaction or order identifiers, or your account identifier in these traffic and purchase-completion events. Separately, our broader product analytics does not receive an account identifier or create person profiles. It uses an abortable, consent-epoch transport rather than relying on the analytics library’s opt-out flag alone. Its accepted-consent browser lane measures page navigation, not page text or form contents; private and unrecognized paths use the same coarse route-family labels described above. While your choice is pending, we do not collect or buffer product-analytics events in browser storage or memory. If you consent, measurement starts with the page you are then viewing; consent does not upload your earlier navigation history. Requests to these providers necessarily include the ordinary technical data any web request carries. Across all of them we keep advertising and cross-site personalization features switched off, we do not build advertising profiles or audiences, and we do not run any custom analytics event that collects your raw browser user-agent string. When you withdraw, we save the site-wide choice first, close new analytics capture, abort in-flight product- analytics requests, invalidate queued and retrying work from the prior consent epoch, clear its local identity and storage, and only then finish applying your preference. This stops further optional analytics transmission to these providers and removes analytics cookies set through our optional analytics category. Withdrawal does not change the lawfulness of processing completed before it.
Retention
- Consented product analytics — retained under PostHog Cloud's provider-managed policy for our plan. PostHog currently reports a seven-year (84-month) product-analytics retention window for our project. Its automatic enforcement is not currently enabled for this project, so we do not describe that window as guaranteed automatic deletion. We verify the provider status at least annually and process verified erasure requests sooner when required. Our business preference remains a 24-month raw-event period, but we do not describe that preference as an implemented control. We may keep annual statistics longer only after irreversible anonymization removes person and device identifiers, small-cell reporting, event-level drill-down, retained re-identification keys, and the ability to join the statistics back to identifiable records.
- Session replay — when collected after consent, replay is sampled and masked as described above. PostHog replay is currently disabled; it may not be enabled until its 30-day setting, masking, sampling, network-capture restrictions, withdrawal behavior, and deletion workflow are verified. Any other replay provider must have its retention and deletion behavior verified before production approval.
- Account + course data — while your account is active, and for 12 months after deletion for fraud and chargeback resolution, unless legal hold requires longer.
- Billing records — 7 years (US tax retention).
- Security logs (truncated IPs, auth events) — at least 12 months, then aggregated.
- Support emails — 2 years.
Security
We follow industry-standard practices for an early-stage SaaS: encryption in transit (TLS 1.2+) and at rest, principle-of- least-privilege access for personnel, mandatory multi-factor authentication for production access, tamper-evident audit logging of administrative actions, and centralized encrypted secrets management. Payment card data is handled exclusively by our PCI DSS Level 1 certified payment processor; we never see or store raw card numbers. We do not publish vendor-specific control names or infrastructure regions on this page; security researchers and enterprise procurement teams can request a security overview by contacting us.
Children & minors
The Service is intended for adults aged 18 and older. We do not knowingly collect personal information from anyone under 18, and the Service is not directed to children or teenagers. If you believe a person under 18 has created an account or provided us data, contact our privacy team and we will terminate the account and delete associated data. If we discover an account belongs to a user under 18, we will terminate and delete it without notice. This restriction applies to free accounts and paid subscriptions alike.
Region-restricted launch waitlists
We are not yet open in the European Union/EEA, United Kingdom, or mainland China. Visitors from those regions may opt in to a launch-notification waitlist by entering their email and checking a consent box on our onboarding page.
Lawful basis. We process your email under your explicit consent (GDPR Article 6(1)(a) for EU/EEA visitors; UK GDPR Article 6(1)(a) for UK visitors; PIPL Article 13(1) for mainland China visitors).
Purpose and limit. We use your email to send you up to three emails related to the opening of your region: one notification when your region opens for customers, and up to two follow-up messages about joining VibeVersity at that point. We will not send general marketing emails, share your email with third parties, or use it beyond this scope. Every email includes a one-click unsubscribe link.
Withdrawal of consent. You may withdraw consent and request deletion at any time by contacting us. Withdrawal is processed within 30 days of receipt.
Retention. We retain your email until you withdraw consent OR until 30 days after the final email in the launch sequence (whichever comes first), at which point we delete it from the waitlist.
Text messages (SMS)
If you give us a mobile number, we may send you text messages about your account and the services you have asked for — for example security and verification codes, account and course notifications, support replies, and, where you have opted in, occasional marketing about new courses, promotions, and offers. We collect a mobile number only when you give it to us, and we do not buy mobile numbers or obtain them from third parties.
We do not sell or share mobile numbers. We do not sell, rent, or share mobile numbers or SMS opt-in data with third parties, affiliates, or lead generators for marketing or promotional purposes. A number is disclosed only to our messaging provider, and only to deliver the messages you have asked for. Consent to receive texts is not a condition of any purchase.
Frequency and rates. Message frequency varies with your account activity and the messages you opt into. Message and data rates may apply. Reply STOP to any message to opt out at any time, or HELP for help. Opting out of texts does not affect your account or your ability to use the service.
Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify active customers by email at least 14 days before the change takes effect. If a change materially expands consent-based analytics, we will ask for your consent again before enabling that expanded processing. Continued use of the Services does not constitute consent to optional analytics.
Contact us
For privacy questions or to exercise your privacy rights, contact our privacy team. For DMCA notices, see our DMCA page.