VisionBoardAI

Privacy Policy

Last revised: August 18, 2026 — Effective: August 19, 2026

1. Information We Collect

When you join the waitlist, we collect:

  • Your email address (required)
  • Your first name (optional)
  • The source of your signup (e.g., UTM campaign parameters, referring URL)
  • Basic technical data: IP address (hashed, not stored in plain text), user agent, timestamp

When you use the VisionBoardAI platform, we additionally collect:

  • Your Vision + Identity Statement and identity pillars
  • Daily protocols, reflections, and behavioral state data you provide
  • Calendar event metadata (if you connect Google Calendar)
  • Voice input for the optional identity statement recording — the audio is stored locally on your device in your browser's IndexedDB (vbai_identity_voice database), scoped to your account. It is not automatically deleted when your account is deleted; to remove it, clear your browser's site data for this site.

2. How We Use Your Information

  • To send you your waitlist confirmation and launch communications
  • To generate your personalized daily protocols using AI
  • To build and update your Identity Graph
  • To improve the product through event-level analytics and aggregate reporting

We do not use your identity data to train shared AI models. We do not sell your data to third parties.

3. Usage Data and Analytics

We collect page_view and other interaction events on our marketing pages and within the platform, even before you sign up or authenticate. This data is stored individually as website_analytics event records.

  • Event properties: May include UTM campaign parameters and referral values.
  • Metadata: Includes your user agent and referrer URL.
  • IP Addresses: Used to generate a hashed IP for rate limiting (e.g., analytics_rate_limits records); raw IPs are not stored.

Retention: There is currently no fixed automated deletion period for website_analytics records.

4. Operational Logging

Our backend services generate operational logs to support security monitoring, debugging, and performance analysis. These logs are stored in Google Cloud Logging.

What is logged per API request:

  • HTTP method and request path (e.g., POST /plan/generate) — query strings are not logged
  • HTTP response status code and request duration in milliseconds
  • A request ID for log correlation: if the caller supplies a valid UUID v4 or the frontend's bounded timestamp-based fallback (req-<timestamp>-<hex>) in the X-Request-Id request header, it is preserved as-is to allow end-to-end trace correlation between frontend telemetry and backend logs; any other value (including free-form strings) is replaced with a freshly generated server-side UUID to prevent log injection
  • Authenticated user UID (for authenticated routes only) — names and email addresses are not included in standard API request logs
  • Timestamp of the request

What is never logged: request bodies, Identity Graph content, reflection text, calendar event content, or any behavioral data you enter into the platform. Email addresses are not logged in standard API request paths; they are also not logged in OAuth integration flows as of July 2026.

Retention: Operational logs are retained for 30 days and then automatically purged under Google Cloud Logging's default retention policy.

5. Error Monitoring

VisionBoardAI uses Sentry (sentry.io) for error monitoring and performance tracking on both the frontend and backend.

Frontend (browser SDK): The Sentry browser SDK captures JavaScript errors and traces performance for approximately 10% of page loads and navigations. It also records Session Replays for approximately 10% of normal sessions and 100% of sessions in which a JavaScript error occurs. Session Replays capture user interactions (mouse movements, clicks, and page navigation) to help diagnose errors; text content in form fields is masked by default using Sentry's privacy controls. The frontend SDK associates events with your authenticated user UID — no email address or personal name is included. We do not intentionally expose personal data to Sentry, but replays may capture anonymized interaction patterns on pages where you are signed in. Unsubscribe link parameters (uid, token, and day-bucket) are scrubbed from Sentry event URLs before transmission.

Backend: When a backend error occurs, Sentry captures: the error type and stack trace, the request path, and the authenticated user's UID (no email, name, or personal content). VisionBoardAI scrubs all OAuth redirect parameters (including authorization codes and CSRF state tokens) from error events before transmission to Sentry, using a beforeSend filter and URL sanitization applied to all backend error reporting.

Sentry event and replay data is retained for 90 days. Sentry's privacy policy is available at sentry.io/privacy.

6. Local Storage & Shared Devices

The VisionBoardAI platform stores certain UI preferences and session state in your browser's local storage (e.g., onboarding progress indicators, focus-mode preferences, and in-progress vision draft slides). If you use VisionBoardAI on a shared or public device, we strongly recommend signing out after each session and clearing your browser data. Local storage is not cleared automatically when you close the browser tab. In-progress draft slides stored locally are not yet synced to your server-side account and will be visible to anyone with access to the browser. Your completed Identity Graph and all finalized personal data remain server-side and are only accessible after authentication.

7. Data Storage & Security

Your data is stored in Google Firebase (Firestore), with industry-standard encryption in transit and at rest. Access is restricted to authenticated users only. Your Identity Graph is private to your account. Server-side security rules block clients from writing to sensitive fields (admin roles, billing status, Stripe IDs, and all Identity Graph collections); account preference fields (theme, notifications) are writable only by the authenticated owner.

8. Data Export & Deletion

You can export your data through the platform. The authorized export includes: daily plans, behavioral scores, reflections (last 30 days of telemetry), and churn-risk records. Your Identity Graph, identity model vectors, and connected integration data are not included in the current export. You can request account deletion by emailing derek@visionboardai.org — we will process deletion requests within 30 days.

9. Third-Party Services

VisionBoardAI uses the following third-party services:

  • Google Firebase — authentication, database, hosting, and cloud functions
  • Google Gemini — AI protocol and reflection generation
  • SendGrid — transactional emails (waitlist confirmation, launch notifications)
  • Sentry — automated backend error monitoring (see Section 5)
  • Stripe — payment processing (only if you subscribe to a paid plan)
  • The following opt-in integration services — connected only when you explicitly enable them in Settings. Each receives only the data necessary to sync with VisionBoardAI:
    • Google Calendar & Google Tasks — calendar event metadata and task lists. Task lists are processed by our AI models to extract identity signals for your Identity Graph and to dynamically incorporate your pending actions into your AI-generated daily schedule. Your Identity Graph is a private, per-user model of your stated goals and behavioral commitments — it is not shared with other users, not used to serve advertising, and not used to train generalized AI models.
    • Microsoft Outlook Calendar — calendar event metadata
    • Strava — activity and fitness data
    • Todoist — task lists
    • Oura — sleep and health metrics
    • Readwise — reading highlights
    • Notion — page and database content you authorize
    None of these integrations are active by default. Google Calendar and Google Tasks can each be disconnected at any time from Settings → Integrations. Disconnecting either integration revokes your OAuth access token at Google and removes all stored credentials from VisionBoardAI.

Google API Services User Data Policy: VisionBoardAI's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

9a. Google API Limited Use

VisionBoardAI's access to Google Calendar and Google Tasks data is subject to the following restrictions, in compliance with the Google API Services User Data Policy:

  • We only use this data to provide the features you explicitly enabled — scheduling conflict detection, daily protocol generation, and calendar write-back. We do not use it for any secondary purpose without your separate consent.
  • We do not use Google user data to serve you advertisements of any kind, including personalized or retargeted ads.
  • We do not allow humans to read your Google Calendar events or Google Tasks data unless you have separately and explicitly granted permission for a specific message, or it is necessary for security purposes (e.g., investigating abuse).
  • We do not transfer Google user data to third parties except as necessary to provide the features you enabled, and only to parties who are contractually bound to the same Limited Use restrictions.
  • We do not use Google user data to train generalized AI models. AI processing of your calendar events and tasks is limited to generating your personal daily protocol and Identity Graph — it is never aggregated across users or used to improve shared models.

10. Cookies

The marketing site (visionboardai.org) uses no tracking cookies. The platform app uses Firebase Authentication, which persists your signed-in session in your browser's IndexedDB and localStorage (not session cookies) by default. This means your authentication state is retained between browser sessions and tabs. On shared or public devices, you must explicitly sign out to clear your session — closing the browser tab alone does not remove it.

11. Contact

For any privacy questions or data requests: derek@visionboardai.org

VisionBoardAI
Home Privacy Terms Contact

© 2026 VisionBoardAI. All rights reserved.