Last revised: August 18, 2026 — Effective: August 19, 2026
When you join the waitlist, we collect:
When you use the VisionBoardAI platform, we additionally collect:
vbai_identity_voice database), scoped to your account. It is not automatically deleted when your account is deleted; to remove it, clear your browser's site data for this site.We do not use your identity data to train shared AI models. We do not sell your data to third parties.
We collect page_view and other interaction events on our marketing pages and within the platform, even before you sign up or authenticate. This data is stored individually as website_analytics event records.
analytics_rate_limits records); raw IPs are not stored.Retention: There is currently no fixed automated deletion period for website_analytics records.
Our backend services generate operational logs to support security monitoring, debugging, and performance analysis. These logs are stored in Google Cloud Logging.
What is logged per API request:
POST /plan/generate) — query strings are not loggedreq-<timestamp>-<hex>) in the X-Request-Id request header, it is preserved as-is to allow end-to-end trace correlation between frontend telemetry and backend logs; any other value (including free-form strings) is replaced with a freshly generated server-side UUID to prevent log injectionWhat is never logged: request bodies, Identity Graph content, reflection text, calendar event content, or any behavioral data you enter into the platform. Email addresses are not logged in standard API request paths; they are also not logged in OAuth integration flows as of July 2026.
Retention: Operational logs are retained for 30 days and then automatically purged under Google Cloud Logging's default retention policy.
VisionBoardAI uses Sentry (sentry.io) for error monitoring and performance tracking on both the frontend and backend.
Frontend (browser SDK): The Sentry browser SDK captures JavaScript errors and traces performance for approximately 10% of page loads and navigations. It also records Session Replays for approximately 10% of normal sessions and 100% of sessions in which a JavaScript error occurs. Session Replays capture user interactions (mouse movements, clicks, and page navigation) to help diagnose errors; text content in form fields is masked by default using Sentry's privacy controls. The frontend SDK associates events with your authenticated user UID — no email address or personal name is included. We do not intentionally expose personal data to Sentry, but replays may capture anonymized interaction patterns on pages where you are signed in. Unsubscribe link parameters (uid, token, and day-bucket) are scrubbed from Sentry event URLs before transmission.
Backend: When a backend error occurs, Sentry captures: the error type and stack trace, the request path, and the authenticated user's UID (no email, name, or personal content). VisionBoardAI scrubs all OAuth redirect parameters (including authorization codes and CSRF state tokens) from error events before transmission to Sentry, using a beforeSend filter and URL sanitization applied to all backend error reporting.
Sentry event and replay data is retained for 90 days. Sentry's privacy policy is available at sentry.io/privacy.
The VisionBoardAI platform stores certain UI preferences and session state in your browser's local storage (e.g., onboarding progress indicators, focus-mode preferences, and in-progress vision draft slides). If you use VisionBoardAI on a shared or public device, we strongly recommend signing out after each session and clearing your browser data. Local storage is not cleared automatically when you close the browser tab. In-progress draft slides stored locally are not yet synced to your server-side account and will be visible to anyone with access to the browser. Your completed Identity Graph and all finalized personal data remain server-side and are only accessible after authentication.
Your data is stored in Google Firebase (Firestore), with industry-standard encryption in transit and at rest. Access is restricted to authenticated users only. Your Identity Graph is private to your account. Server-side security rules block clients from writing to sensitive fields (admin roles, billing status, Stripe IDs, and all Identity Graph collections); account preference fields (theme, notifications) are writable only by the authenticated owner.
You can export your data through the platform. The authorized export includes: daily plans, behavioral scores, reflections (last 30 days of telemetry), and churn-risk records. Your Identity Graph, identity model vectors, and connected integration data are not included in the current export. You can request account deletion by emailing derek@visionboardai.org — we will process deletion requests within 30 days.
VisionBoardAI uses the following third-party services:
Google API Services User Data Policy: VisionBoardAI's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
VisionBoardAI's access to Google Calendar and Google Tasks data is subject to the following restrictions, in compliance with the Google API Services User Data Policy:
The marketing site (visionboardai.org) uses no tracking cookies. The platform app uses Firebase Authentication, which persists your signed-in session in your browser's IndexedDB and localStorage (not session cookies) by default. This means your authentication state is retained between browser sessions and tabs. On shared or public devices, you must explicitly sign out to clear your session — closing the browser tab alone does not remove it.
For any privacy questions or data requests: derek@visionboardai.org