Privacy Policy
Effective date: July 14, 2026
Last updated: August 20, 2026
vibestackbuilder.com
1. Who this covers and who we are
This Privacy Policy explains what personal data Power In Numbers Flagship Company, LLP, a Texas limited liability partnership doing business as VibeStack Builder™ ("VibeStack Builder™," "we," "us," or "our"), collects when you use vibestackbuilder.com and the VibeStack Builder™ platform (the "Service"), why we collect it, who we share it with, how long we keep it, and what rights you have.
Two different roles, and the difference matters.
For your VibeStack Builder™ account and your projects on our platform, we are the controller. We decide what we collect and why, and this policy governs.
For the data inside the apps we build for you, you are the controller and we are the processor. We act on your instructions and hold no independent rights over it. Your app's data lives in your own Airtable or Supabase account. We do not copy it, index it, or read it. This policy does not govern how you handle your app users' data; that is your responsibility, and you need your own privacy policy for it.
2. Personal data we collect
Account data. Your email address and a password hash (via Supabase Auth). If you sign in through a third-party identity provider, the identifiers that provider returns.
Project data. Your idea description, your interview conversation, the blueprint, the decision log, the build history, and the plain-English build feed.
Service credentials. The API keys and tokens you connect for Anthropic, GitHub, Railway, Airtable, and Supabase. These are stored envelope-encrypted. We cannot read them at rest; they are decrypted only in server memory at the moment of use and never shown to anyone, including you (you see the last four characters only). Disconnecting a service crypto-shreds the stored key immediately and irreversibly.
Billing data. Your plan, subscription status, billing history, and the Stripe customer identifier. Stripe processes and holds your card details; we never see or store your card number.
Usage and technical data. Platform usage records for the free tier, log data, IP address, browser and device type, timestamps, pages viewed, and error and diagnostic events.
Communications. Support requests, emails you send us, and our replies.
Sensitive personal data. We do not intentionally collect sensitive personal data as that term is defined by Texas, California, or European law: no racial or ethnic origin, religious belief, mental or physical health diagnosis, sexuality, citizenship or immigration status, genetic or biometric data, precise geolocation, or data known to concern a child under 13. Please do not put sensitive personal data into a project description, an interview answer, or a support request.
In California's statutory categories, the data above falls into: identifiers (email address, IP address, account and customer identifiers); commercial information (plan, subscription, and billing records); internet or other electronic network activity (usage records, log and diagnostic data); and, where you choose to include it, professional or employment-related information and other information you volunteer in a project description or support request. We collect no other statutory category and no sensitive personal information.
De-identified and aggregated data. We may create de-identified or aggregated statistics about how the Service is used, such as counts of builds or error rates. We maintain and use that data without attempting to re-identify anyone, and we contractually require anyone who receives it to do the same.
3. What we do not collect
Your app's own data. The customers, orders, bookings, or anything else your built app tracks lives in your database on your account. We do not copy it, index it, or read it.
Card numbers. Stripe holds them.
Plaintext credentials. Ever.
We also do not collect biometric identifiers, we do not buy personal data from data brokers, and we do not operate advertising or analytics tracking on the Service.
4. Where the data comes from
Directly from you when you register, build, subscribe, or contact us; automatically from your device and browser when you use the Service; and from Stripe (billing status) and any identity provider you use to sign in.
5. Why we process it
We process personal data to:
- Create and administer your account and authenticate you;
- Run interviews, generate blueprints, and build and deploy your apps;
- Act on your Connected Services with the credentials you supply;
- Process payments, manage subscriptions, and prevent payment fraud;
- Provide support and respond to your requests;
- Enforce plan limits and detect abuse of the free tier;
- Keep the Service secure, debug it, and improve its reliability and performance;
- Send you transactional and service messages, including renewal, billing, and security notices; and
- Comply with law and establish, exercise, or defend legal claims.
We do not use your personal data or your project content to train artificial intelligence models.
6. Legal bases (for people in the EEA, the United Kingdom, and Switzerland)
We rely on: contract (Art. 6(1)(b) GDPR) to provide the Service you signed up for, including account, build, and billing processing; legitimate interests (Art. 6(1)(f)) for security, abuse prevention, debugging, and service improvement, balanced against your rights; legal obligation (Art. 6(1)(c)) for tax, accounting, and lawful requests; and consent (Art. 6(1)(a)) where we ask for it, which you may withdraw at any time without affecting processing already carried out.
7. AI processing
Interview messages and blueprint content are sent to Anthropic's API to generate responses, on our key for free blueprints and on your key once connected. AI (Claude by Anthropic) does the building; screens displaying model output say so.
You are interacting with an artificial intelligence system, not a human being, when you use the interview, the build feed, and the other AI-driven parts of the Service. AI output can be wrong.
We do not use automated decision-making that produces legal or similarly significant effects about you within the meaning of Art. 22 GDPR. The AI generates software; it does not decide anything about your rights, your eligibility, or your access to the Service.
Anthropic processes this content under its own terms and privacy policy, which you should read: https://www.anthropic.com/legal/privacy
8. Sub-processors and who we share with
Categories of personal data we share: account identifiers, project content, usage and technical data, and billing status, each only with the sub-processor whose role requires it.
Categories of third parties we share with, and what each does:
| Sub-processor | Role | What it processes |
|---|---|---|
| Anthropic, PBC | AI processing | Interview and build content |
| Supabase, Inc. | Database and authentication | Account and project data |
| Railway Corp. | Hosting | Platform infrastructure and logs |
| Stripe, Inc. | Payments | Billing and payment data |
| Resend, Inc. | Transactional email | Email address and message content |
Each processes only what its role requires. Each is bound by a written agreement to process personal data only on our instructions and to keep it secure.
We may also share personal data:
- With you and at your direction, including to the Connected Services you authorize;
- With professional advisers (lawyers, accountants, auditors) under confidentiality;
- In a business transaction, if we are involved in a merger, acquisition, financing, reorganization, or sale of assets, subject to this policy continuing to apply; and
- For legal reasons, to comply with law, a subpoena, or a court order, to enforce our Terms, or to protect the rights, property, or safety of any person. We will notify you of a legal demand for your data unless we are legally prohibited from doing so.
9. We do not sell your personal data
We do not sell your personal data, and we do not share it for cross-context behavioral advertising or targeted advertising, as those terms are defined by Texas and California law. We do not profile you in furtherance of decisions that produce legal or similarly significant effects. We have not sold or shared personal data in the preceding 12 months, including the personal data of anyone we know to be under 16.
Because we do not sell personal data, the statutory sale notices required by Tex. Bus. & Com. Code § 541.102(b) and (c) do not apply to us. If that ever changes, we will post the required notice here before we do it and give you a way to opt out.
10. Cookies
Authentication session cookies only. No third-party advertising or analytics cookies in v1.
We honor browser-level opt-out preference signals, including Global Privacy Control, as an opt-out of any sale or targeted advertising, though we do not conduct either. If we add analytics or other non-essential cookies, we will update this policy and, where the law requires it, ask for your consent first.
11. How long we keep it
| Data | Retention |
|---|---|
| Account data | For the life of your account, then deleted within 30 days of closure |
| Project data, blueprints, decision logs | For the life of your account, then deleted within 30 days of closure |
| Service credentials | Until you disconnect the service or close your account, then crypto-shredded immediately |
| Billing records | 7 years, as tax and accounting law requires |
| Logs and security records | 90 days, or longer where needed for an open security investigation |
| Support communications | 24 months |
Backups containing deleted data are overwritten in the ordinary backup cycle, within 35 days.
12. Security
We use envelope encryption for stored credentials, encryption in transit, access controls limiting staff access to what their role requires, and logging and monitoring. No system is perfectly secure, and we cannot guarantee absolute security.
If a breach of system security affects your sensitive personal information, we will notify you as Texas law requires under Tex. Bus. & Com. Code § 521.053, without unreasonable delay and no later than 60 days after we determine a breach occurred, and we will notify the Texas Attorney General within 30 days where the breach involves at least 250 Texas residents. Where other law imposes a shorter deadline or a different standard, we will meet it.
13. Your rights, including erasure
You can export your blueprints and decision logs at any time (they are yours). Deleting your account cascades: profile, projects, conversations, blueprints, build history, and every stored credential is crypto-shredded. Your deployed apps are untouched by deletion because they run on your accounts.
If you are a Texas resident, the Texas Data Privacy and Security Act gives you the right to: confirm whether we process your personal data and access it; correct inaccuracies; delete personal data you provided or we obtained about you; obtain a portable copy in a readily usable format where processing is automated; and opt out of processing for targeted advertising, sale, or profiling in furtherance of decisions producing legal or similarly significant effects. We do not do any of those last three, so there is nothing to opt out of, but the right stands. We will not discriminate against you for exercising these rights.
If you are a California resident, you have the rights to know, access, correct, delete, obtain a portable copy, opt out of sale or sharing, and limit the use of sensitive personal information, plus the right to be free from retaliation for exercising them. We do not sell or share personal information and do not use sensitive personal information for any purpose requiring a limitation right.
If you live in Colorado, Connecticut, Virginia, Utah, Oregon, Montana, or another state with a comprehensive privacy law, you have substantially the same rights, and we will honor them on the same terms.
If you are in the EEA, the UK, or Switzerland, you have the rights of access, rectification, erasure, restriction, portability, and objection, including objection to processing based on legitimate interests, and the right to withdraw consent.
14. How to exercise your rights
Email: stackbuilder_privacy@power-in-numbers.net
You do not need an account to submit a request. We will verify your identity before acting, usually by confirming control of the email address on the account. If we cannot verify you, we will tell you and explain why.
Our timeline. We will respond within 45 days. If the request is complex, we may extend once by another 45 days and will tell you why before the first period ends. Your first two requests in a 12-month period are free.
Authorized agents. You may use an authorized agent. We will ask the agent for proof of authority and may ask you to confirm it directly.
15. If we say no: your right to appeal
If we decline your request, we will tell you why and how to appeal. To appeal, reply to our decision or write to stackbuilder_appeals@power-in-numbers.net within 60 days. We will review and respond in writing within 60 days, explaining the reasoning.
If we deny your appeal, you may submit a complaint to the Texas Attorney General at https://www.texasattorneygeneral.gov/consumer-protection/file-consumer-complaint/consumer-privacy-rights, or to the regulator in your own state.
If you are in the EEA or the UK, you may lodge a complaint with your local supervisory authority or the UK Information Commissioner's Office. We would appreciate the chance to address it first.
16. International transfers
We are based in the United States and process personal data there. Our sub-processors may process it in the United States and elsewhere. If you are in the EEA, the UK, or Switzerland, we transfer personal data out of your region using the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or another lawful transfer mechanism, together with supplementary measures where appropriate. You may request a copy of the relevant safeguards at stackbuilder_privacy@power-in-numbers.net.
17. Children
The Service is not directed to children, and you must be at least 18 to use it. We do not knowingly collect personal data from anyone under 18. If you believe a child has given us personal data, write to stackbuilder_privacy@power-in-numbers.net and we will delete it. We do not sell or share the personal data of anyone under 16.
If you build an app directed to children, complying with the Children's Online Privacy Protection Act and equivalent law is your responsibility as that app's operator.
18. Do Not Track
Browsers send Do Not Track signals inconsistently and there is no agreed standard for honoring them, so we do not respond to them. We do honor Global Privacy Control, as described in Section 10.
19. Changes to this policy
We may update this policy. If a change is material, we will give you notice by email or in-product notice at least 30 days before it takes effect, and we will update the "Last updated" date above. Continuing to use the Service after that date means you accept the updated policy.
20. Contact us
Power In Numbers Flagship Company, LLP d/b/a VibeStack Builder™
2800 Post Oak Blvd Suite 5600, Houston, TX 77056
- Privacy questions and requests: stackbuilder_privacy@power-in-numbers.net
- Appeals: stackbuilder_appeals@power-in-numbers.net
- Abuse reports: stackbuilder_abuse@power-in-numbers.net