vibivibi

Privacy Policy · Terms of Service

Privacy Policy

Effective 2026-10-03

vibivibi ("the Service") is operated by Subconscious Systems Technologies ("we"). The Service stores coding-agent sessions that are encrypted on your machine before they reach us and moves them between your machines and the people you choose. This policy explains what we can and cannot see, what we keep, and why.

The short version: the contents of your sessions are encrypted with keys we never have, so we cannot read them. We do see account details, billing details and the metadata needed to run the Service, listed below.

1. What we cannot see

Session transcripts, session titles, working directories and model names are encrypted on your machine by the vibi client with AES-256-GCM under a key that is itself wrapped for your X25519 public key and for the public keys of the people you send a session to. Your private key is stored with us only in encrypted form, wrapped with a key derived from your encryption password (scrypt). The password never leaves your machine and we have no copy of it.

We therefore cannot read, search, scan, moderate or recover the contents of any session, including on request from you, and cannot restore access if you lose your encryption password. There is no administrative or support path around this.

2. What we collect and store

Account. Your email address, display name and the sign-in method you use (email, Google, GitHub or X), handled through our authentication provider. We never see passwords used to sign in.

Billing. Plan, subscription status, seat count and a customer reference at our payment provider. Card details are entered on the payment provider's pages and are not stored by us.

Machines. For every machine you enroll: the name you gave it, operating system, hostname, CPU architecture, client version, enrollment and last-activity times, and a hash of its device token.

Encryption key. Your public key, its fingerprint, and your private key in encrypted form as described above.

Session metadata. For every stored session: which agent produced it, the agent's own session id, size in bytes, timestamps, which machine pushed each version, which key fingerprints each version is encrypted for, whom you sent it to, and the optional plain-text name you type when you push it. The name is the one thing about a session that is stored unencrypted; choose it accordingly.

Encrypted content. The ciphertext of each session version, stored in a private object store.

Usage and notifications. Bytes downloaded, storage held over time, plan limits, and the notifications shown in your dashboard (subscription, team and sharing events).

Invitations and contacts. Email addresses you enter when inviting people or sending them sessions, and who you have exchanged sessions with.

Technical logs. Our hosting provider records request logs (IP address, user agent, timestamps, requested paths) for a limited period for security and debugging.

3. How we use it

  • To provide the Service: store and deliver encrypted sessions, enroll machines, deliver sessions to the recipients you choose.
  • To bill you and enforce plan limits (storage, machines, downloads, versions, seats).
  • To send transactional messages: invitations you trigger, and in-app notifications about your account, team and sessions.
  • To keep the Service secure: detect abuse, revoke compromised devices, investigate incidents.
  • To respond when you contact us.

5. Who we share it with

We do not sell personal data. We use these providers to run the Service, each of which processes only what its role requires:

  • Vercel — application hosting, request logs, and the private object store that holds encrypted session content.
  • Neon — the database holding account, machine, key and metadata records.
  • Clerk — sign-in, sign-up, session cookies, and the invitation emails sent on your behalf.
  • Stripe — payments, invoices, subscription management.

People you send a session to receive a copy encrypted for their key; team owners on the Team plan can see your session metadata (names, sizes, recipients) but never the contents. We may disclose data if required by law; because content is encrypted with keys we do not hold, we can only ever hand over ciphertext and the metadata listed above.

6. Retention and deletion

Stored sessions are kept until you delete them, until an older version is pruned under your plan's version retention, or until you delete your account. Deleting a session removes its ciphertext and metadata and any shares of it. Deleting your account removes every session you own and their ciphertext, the sessions others sent you, your machines and device tokens, your encryption key, invitations, contacts, notifications and usage records; your team is deleted if you were its only member. A minimal record of the account (an anonymised user id) is retained so that audit entries remain consistent.

Database backups kept by our database provider may contain deleted records for up to 7 days before they expire. Payment records are retained as long as tax and accounting law require.

7. Security

  • All traffic uses HTTPS. Device tokens are stored hashed; enrollment codes are single-use and expire in minutes.
  • Session content is end-to-end encrypted as described above; the server verifies ciphertext integrity (SHA-256) but never decrypts it.
  • You can revoke any machine from the dashboard; its device token stops working immediately.
  • If you keep the decrypted key on a machine (a choice you make at enrollment), anyone with access to that machine's user account can read your sessions there. vibi lock removes it.

8. Your choices and rights

  • Access and portability: every session you own can be pulled in its original form with vibi pull; account details are visible under Settings.
  • Correction: change your name under Settings and your email through the account menu.
  • Deletion: delete individual sessions from the Sessions page or the whole account under Settings; both take effect immediately.
  • Objection and complaints: contact us at support@subconscious.dev. EEA/UK users may also complain to their local data protection authority.

9. Cookies

We use only the cookies needed to keep you signed in (set by our authentication provider) and for payment pages (set by our payment provider while you are on them). There are no advertising or cross-site tracking cookies.

10. International transfers

The Service is hosted in the United States. If you use it from elsewhere, your data is transferred there. Our providers offer standard contractual clauses or equivalent safeguards for such transfers.

11. Children

The Service is not directed at children and may not be used by anyone under 16. We delete accounts we learn belong to someone younger.

12. Changes to this policy

We will post changes here and update the effective date. For changes that reduce your rights or expand what we collect, we will notify you in the dashboard or by email before they take effect.

Questions: support@subconscious.dev. Subconscious Systems Technologies, 1 Broadway, 14th Floor, Cambridge, MA 02142, USA.