Privacy Policy
Last updated: March 4, 2026
1. Introduction
Welcome to VibeDash. We respect your privacy and are committed to protecting your personal data. This privacy policy explains how we collect, use, disclose, and safeguard your information when you use our platform.
2. Information We Collect
We may collect the following types of information:
- Account Information: Name, email address, and authentication credentials when you create an account.
- Project Data: Information about your projects, including project names, descriptions, phases, and related metadata you input into VibeDash.
- Third-Party Integrations: Data from connected services such as GitHub repositories and Google Analytics, which you explicitly authorize.
- Usage Data: Information about how you interact with our platform, including pages visited, features used, and session duration.
- Device Information: Browser type, operating system, IP address, and device identifiers.
3. Google User Data — Accessed, Used, Stored & Shared
VibeDash integrates with Google Analytics via the Google APIs. This section specifically addresses how we handle data received from Google APIs in compliance with the Google API Services User Data Policy, including the Limited Use requirements.
3.1 Data Accessed
When you connect a Google Analytics property to VibeDash, we request the analytics.readonly OAuth scope. This grants us read-only access to the following Google Analytics 4 data for the property you select:
- Active Users: Monthly active users (last 30 days) and yearly active users (last 365 days).
- Daily Visitor Counts: A day-by-day breakdown of active users over the last 30 days.
- Top Pages: The top 10 pages by pageviews over the last 30 days (page paths and view counts only).
- Account & Property Metadata: A list of GA4 property names and IDs accessible to your Google account, so you can choose which property to link.
We do not access personally identifiable information of your website visitors, demographic reports, remarketing audiences, or any data outside the read-only analytics scope listed above.
3.2 Data Usage
Google Analytics data retrieved through the Google APIs is used solely to:
- Display analytics dashboards and traffic charts within your VibeDash project.
- Provide AI-powered insights and recommendations about your project's traffic trends.
- Include summary metrics (e.g., monthly visitors) in optional email reports you enable.
We do not use Google user data for advertising, marketing profiling, or any purpose unrelated to providing and improving VibeDash's core functionality for you.
3.3 Data Sharing
We do not sell, rent, or share Google user data with any third parties, except in the following limited circumstances:
- Infrastructure Providers: Google Analytics data may pass through our hosting provider (Vercel) and database provider (MongoDB Atlas) solely for the purpose of operating the VibeDash service. These providers act as data processors under contractual obligations to protect your data.
- AI Processing: Aggregated, non-identifiable analytics metrics (e.g., visitor counts) may be sent to our AI service provider to generate project insights. No raw Google user tokens or personally identifiable information are shared.
- Legal Obligations: When required by law, valid legal process, or to protect our rights.
Google user data is never shared with third parties for purposes unrelated to providing or improving VibeDash.
3.4 Data Storage & Protection
OAuth tokens (access tokens and refresh tokens) obtained through the Google authorization flow are stored securely in our MongoDB Atlas database, which is hosted in a SOC 2–compliant environment with encryption at rest (AES-256) and encryption in transit (TLS 1.2+). Access to stored tokens is restricted to authenticated, per-user, per-project lookups — no user can access another user's Google data.
Cached analytics data (visitor counts, top pages) is stored alongside your project record in the same database with the same security controls. All communication between VibeDash and Google APIs occurs over HTTPS.
3.5 Data Retention & Deletion
We retain Google Analytics tokens and cached analytics data for as long as your Google Analytics connection remains active within VibeDash. You can disconnect Google Analytics from any project at any time through the VibeDash dashboard, which immediately deletes the stored OAuth tokens and cached analytics data for that project.
If you delete your VibeDash account, all associated Google Analytics tokens and cached data are permanently deleted. You may also revoke VibeDash's access at any time from your Google Account permissions page.
To request deletion of your data, contact us at support@vibedash.app and we will process your request within 30 days.
4. How We Use Your Information
We use the information we collect to:
- Provide, operate, and maintain the VibeDash platform.
- Personalize your experience and deliver AI-powered insights.
- Process transactions and manage your subscription.
- Send you service-related communications, such as daily summaries and alerts.
- Improve our platform, develop new features, and fix bugs.
- Ensure security and prevent fraud.
5. Data Sharing & Disclosure
We do not sell your personal data. We may share your information only in the following circumstances:
- Service Providers: With trusted third-party vendors who assist us in operating our platform (e.g., hosting, analytics, payment processing).
- Legal Compliance: When required by law or in response to valid legal processes.
- Business Transfers: In connection with a merger, acquisition, or sale of assets.
6. Data Security
We implement industry-standard security measures to protect your data, including encryption in transit (TLS 1.2+) and at rest (AES-256), secure authentication via Clerk, and regular security audits. However, no method of transmission over the Internet is 100% secure.
7. Data Retention
We retain your personal data for as long as your account is active or as needed to provide you services. You may request deletion of your data at any time by contacting us at support@vibedash.app. We will process deletion requests within 30 days.
8. Your Rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request deletion of your data.
- Object to or restrict processing of your data.
- Data portability — receive your data in a structured, machine-readable format.
9. Cookies
We use essential cookies to maintain your session and preferences. We may also use analytics cookies to understand usage patterns. You can manage cookie preferences through your browser settings.
10. Third-Party Services
VibeDash integrates with third-party services such as GitHub and Google Analytics. These services have their own privacy policies, and we encourage you to review them. We only access data you explicitly authorize through OAuth or similar mechanisms.
11. Changes to This Policy
We may update this privacy policy from time to time. We will notify you of any material changes by posting the new policy on this page and updating the "Last updated" date.
12. Contact Us
If you have any questions about this privacy policy or wish to exercise your data rights, please contact us at support@vibedash.app.