Privacy Policy · Terms of Service
Privacy Policy
Effective 2026-10-03
vibivibi ("the Service") is operated by Subconscious Systems Technologies ("we"). The Service stores coding-agent sessions that are encrypted on your machine before they reach us and moves them between your machines and the people you choose. This policy explains what we can and cannot see, what we keep, and why.
The short version: the contents of your sessions are encrypted with keys we never have, so we cannot read them. We do see account details, billing details and the metadata needed to run the Service, listed below.
1. What we cannot see
Session transcripts, session titles, working directories and model names are encrypted on your machine by the vibi client with AES-256-GCM under a key that is itself wrapped for your X25519 public key and for the public keys of the people you send a session to. Your private key is stored with us only in encrypted form, wrapped with a key derived from your encryption password (scrypt). The password never leaves your machine and we have no copy of it.
We therefore cannot read, search, scan, moderate or recover the contents of any session, including on request from you, and cannot restore access if you lose your encryption password. There is no administrative or support path around this.
2. What we collect and store
Account. Your email address, display name and the sign-in method you use (email, Google, GitHub or X), handled through our authentication provider. We never see passwords used to sign in.
Billing. Plan, subscription status, seat count and a customer reference at our payment provider. Card details are entered on the payment provider's pages and are not stored by us.
Machines. For every machine you enroll: the name you gave it, operating system, hostname, CPU architecture, client version, enrollment and last-activity times, and a hash of its device token.
Encryption key. Your public key, its fingerprint, and your private key in encrypted form as described above.
Session metadata. For every stored session: which agent produced it, the agent's own session id, size in bytes, timestamps, which machine pushed each version, which key fingerprints each version is encrypted for, whom you sent it to, and the optional plain-text name you type when you push it. The name is the one thing about a session that is stored unencrypted; choose it accordingly.
Encrypted content. The ciphertext of each session version, stored in a private object store.
Usage and notifications. Bytes downloaded, storage held over time, plan limits, and the notifications shown in your dashboard (subscription, team and sharing events).
Invitations and contacts. Email addresses you enter when inviting people or sending them sessions, and who you have exchanged sessions with.
Technical logs. Our hosting provider records request logs (IP address, user agent, timestamps, requested paths) for a limited period for security and debugging.
3. How we use it
- To provide the Service: store and deliver encrypted sessions, enroll machines, deliver sessions to the recipients you choose.
- To bill you and enforce plan limits (storage, machines, downloads, versions, seats).
- To send transactional messages: invitations you trigger, and in-app notifications about your account, team and sessions.
- To keep the Service secure: detect abuse, revoke compromised devices, investigate incidents.
- To respond when you contact us.
4. Legal basis (EEA/UK users)
We process account, machine, key, metadata and content data to perform our contract with you; billing data to perform the contract and meet legal obligations; technical logs and abuse detection on the basis of our legitimate interest in running a secure service. We do not rely on consent for any of the above and do not use your data for advertising or profiling.
6. Retention and deletion
Stored sessions are kept until you delete them, until an older version is pruned under your plan's version retention, or until you delete your account. Deleting a session removes its ciphertext and metadata and any shares of it. Deleting your account removes every session you own and their ciphertext, the sessions others sent you, your machines and device tokens, your encryption key, invitations, contacts, notifications and usage records; your team is deleted if you were its only member. A minimal record of the account (an anonymised user id) is retained so that audit entries remain consistent.
Database backups kept by our database provider may contain deleted records for up to 7 days before they expire. Payment records are retained as long as tax and accounting law require.
7. Security
- All traffic uses HTTPS. Device tokens are stored hashed; enrollment codes are single-use and expire in minutes.
- Session content is end-to-end encrypted as described above; the server verifies ciphertext integrity (SHA-256) but never decrypts it.
- You can revoke any machine from the dashboard; its device token stops working immediately.
- If you keep the decrypted key on a machine (a choice you make at enrollment), anyone with access to that machine's user account can read your sessions there.
vibi lockremoves it.
8. Your choices and rights
- Access and portability: every session you own can be pulled in its original form with
vibi pull; account details are visible under Settings. - Correction: change your name under Settings and your email through the account menu.
- Deletion: delete individual sessions from the Sessions page or the whole account under Settings; both take effect immediately.
- Objection and complaints: contact us at support@subconscious.dev. EEA/UK users may also complain to their local data protection authority.
10. International transfers
The Service is hosted in the United States. If you use it from elsewhere, your data is transferred there. Our providers offer standard contractual clauses or equivalent safeguards for such transfers.
11. Children
The Service is not directed at children and may not be used by anyone under 16. We delete accounts we learn belong to someone younger.
12. Changes to this policy
We will post changes here and update the effective date. For changes that reduce your rights or expand what we collect, we will notify you in the dashboard or by email before they take effect.
Questions: support@subconscious.dev. Subconscious Systems Technologies, 1 Broadway, 14th Floor, Cambridge, MA 02142, USA.