PRIVACY POLICY
Last updated: June 12, 2026 · Effective at launch.
This Privacy Policy explains how Alva Systems Architecture LLC, doing business as VibeVault (“VibeVault,” “we,” “us,” or “our”), collects, uses, and protects information about you when you use our service at vibevaultapp.com. Questions? Email [email protected].
1. WHAT WE COLLECT
Account data (registered users)
- Email address and display name
- OAuth provider identifiers (Google subject ID, Spotify user ID) when you sign in via Google or Spotify
- Hashed password (bcrypt, never stored in plain text) when you sign in via email and password
- TOTP MFA secret (encrypted) if you enable two-factor authentication
- IP address at account creation and at deletion request (stored as a one-way hash)
- Account type, organization membership, and role
Event & request activity
- Song requests you submit, including optional display name and message text
- Boost credit transactions (credits spent, event, timestamp)
- Events you create or manage as a DJ or organization operator
- Spotify playback state (what’s currently playing, queue) associated with your DJ account
Analytics (pseudonymized)
We self-host PostHog on our own servers. Analytics data never leaves our infrastructure and is never shared with advertising networks. We collect:
- Page views, feature interactions, and funnel events (e.g.,
request_submitted,event_created) - Song search events identified only by query length (integer) — never the search text itself
- Session metadata (browser type, screen size, referrer) for debugging and product improvement
PostHog events contain no direct identifiers (name, email, phone). We use pseudonymous distinct IDs that cannot be easily reversed to a real person without access to the VibeVault database.
Cookies & local storage
We use strictly necessary session cookies for authentication and local storage for your cookie consent preference. With your consent we also set analytics cookies for PostHog. See our Cookie Policy for details.
2. HOW WE USE YOUR INFORMATION
- To create and manage your account and authenticate your sessions
- To operate the song-request queue and deliver the service
- To process credit purchases and manage your credit balance (via Stripe when billing is active)
- To send transactional email: account verification, password reset, deletion grace-period reminders, and receipt confirmations (via Resend)
- To analyse product usage in aggregate (PostHog) so we can improve the platform
- To detect and prevent abuse, fraud, and Terms of Service violations
- To comply with legal obligations, including responding to valid legal requests
We do not sell your personal information. We do not use your information for targeted advertising.
3. LEGAL BASES FOR PROCESSING (GDPR)
For users in the European Economic Area (EEA) or United Kingdom, we process personal data under the following legal bases:
- Contract performance— to provide the service you signed up for (account management, request processing, billing)
- Legitimate interests— for security, fraud prevention, abuse detection, and aggregate product analytics (balanced against your rights; we apply data minimisation and pseudonymisation)
- Legal obligation— to comply with applicable law
- Consent— for non-essential analytics cookies (which you can withdraw at any time via the cookie preferences panel)
4. WHO WE SHARE YOUR INFORMATION WITH
We share data only with the service providers (processors) needed to run VibeVault. They act on our instructions and are contractually prohibited from using your data for their own purposes.
Supabase (database & authentication)
Hosts our Postgres database and authentication layer. Your account data, event records, and request history are stored here. Supabase is SOC 2 Type II certified. Data is stored in the US-East-1 region.
Resend (transactional email)
Receives your email address to deliver account verification, password reset, and deletion-reminder emails. Resend does not use your email for marketing.
Stripe (payments)
Processes credit purchases and subscription billing when payment features are active. Stripe stores your payment card details; we store only the Stripe customer ID and transaction metadata. Stripe is PCI DSS Level 1 certified.
Spotify AB (music API)
If you connect a Spotify account, we exchange OAuth tokens with Spotify to enable playback control and catalog search. Spotify’s own Privacy Policy governs data held by Spotify. We store only an encrypted refresh token and your Spotify display name.
PostHog (self-hosted analytics)
Our PostHog instance runs on servers we own and operate. Analytics data never leaves our infrastructure. PostHog is not a third-party processor for this purpose.
We may also disclose information if required by law, subpoena, or court order, or to protect the safety of users or the public.
5. CHILDREN’S PRIVACY (COPPA)
VibeVault is not directed at children under 13. We do not knowingly collect personal information from children under 13 years of age. All account registration paths require users to confirm they are at least 13 years old before an account is created. If a user indicates they are under 13, no account is created and no personal data is retained.
Our launch events include community activities (such as school swim meets) where children under 13 may be physically present. In these contexts:
- Children under 13 may attend an event and have an adult submit requests on their behalf using the adult’s account.
- Children under 13 should not create their own accounts or submit requests directly.
- Event display screens (now-playing, queue) may be visible to all attendees and contain only song titles, artist names, and pseudonymous display names provided by guests.
We do not serve behavioral advertising to anyone on VibeVault, and particularly not to minors. We do not build advertising profiles.
If you are a parent or guardian and believe your child under 13 has created an account, please contact [email protected]. We will verify and delete the account and any associated data promptly.
6. DATA RETENTION & ACCOUNT DELETION
We retain your personal data for as long as your account is active or as needed to provide the service. When you request account deletion:
- Your account is immediately suspended (you cannot log in or submit requests) and a 30-day grace period begins.
- You will receive a confirmation email. A reminder email is sent 7 days before permanent deletion.
- During the grace period you can cancel deletion from the deletion confirmation email or by contacting support.
- After 30 days, all personal data associated with your account is permanently deleted, including account details, event history, and request records.
- A minimal tombstone recordis retained indefinitely. It contains only a one-way cryptographic hash of your email address and user ID — it cannot be reversed to recover your identity. This record exists solely to prevent promotion re-use on re-registration and to support fraud-detection obligations.
Any unused credit balance is forfeited at deletion (credits are non-refundable per our Terms of Service).
We may retain certain data longer where required by law (e.g., financial transaction records required by tax law), in which case access is restricted to that compliance purpose only.
7. YOUR RIGHTS (CCPA & GDPR)
Depending on where you live, you may have some or all of the following rights regarding your personal data:
- Access: Request a copy of the personal data we hold about you.
- Correction: Ask us to correct inaccurate or incomplete information.
- Deletion: Request deletion of your account and personal data (subject to the 30-day grace period described above).
- Data portability: Receive your data in a machine-readable format.
- Objection / restriction: Object to or restrict certain processing (e.g., analytics) where we rely on legitimate interests.
- Withdraw consent: Withdraw consent for analytics cookies at any time via the cookie preferences panel without affecting the lawfulness of prior processing.
- California residents (CCPA/CPRA): You have the right to know what personal information we collect and share, to delete it, to correct it, to opt out of sale (we do not sell your data), and to non-discrimination for exercising your rights.
Most rights can be exercised directly from your account settings. To submit a rights request or if you have questions, email [email protected]. We respond within 30 days (45 days for complex requests with notice).
EEA/UK users who believe their rights have not been respected may lodge a complaint with their local supervisory authority.
8. COOKIES
We use strictly necessary cookies to keep you logged in and to remember your cookie preferences. With your consent (asked on your first visit) we also set analytics cookies for our self-hosted PostHog instance.
We do not use advertising cookies or share cookie data with ad networks. You can change your cookie preferences at any time by clicking “Cookie preferences” in the site footer or by reviewing our full Cookie Policy.
9. INTERNATIONAL DATA TRANSFERS
VibeVault is operated from the United States. If you access the service from outside the US, your information will be transferred to and processed in the United States. For EEA/UK users, transfers to Supabase (US-East-1) occur under standard contractual clauses or an equivalent transfer mechanism.
Because we self-host PostHog on our own servers in the United States, analytics data does not flow to a third country beyond the US.
10. SECURITY
We implement reasonable technical and organizational safeguards to protect your personal data, including:
- TLS encryption in transit (via Cloudflare)
- Passwords hashed with bcrypt; never stored in plain text
- Spotify refresh tokens encrypted at the application layer (AES-GCM)
- Row-level security (RLS) in the database — users can only access their own data
- Credit-spending and account-deletion operations gated behind server-only SECURITY DEFINER functions
- Platform admin capability isolated from client-side queries
No system is perfectly secure. If you believe you have found a security vulnerability, please report it responsibly to [email protected].
11. CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time. We will update the “Last updated” date at the top of this page and, for material changes, notify registered users by email before the change takes effect. We encourage you to review this page periodically.
12. CONTACT & HOW TO EXERCISE YOUR RIGHTS
For privacy questions, data access/deletion requests, or to withdraw consent:
Alva Systems Architecture LLC
Privacy inquiries: [email protected]
General support: [email protected]
Website: vibevaultapp.com
We aim to respond to privacy inquiries within two business days and to complete verified rights requests within 30 days.