Privacy

What ViBo keeps about you, and what it does not.

ViBo is a vision board you build on an infinite canvas. To do that it has to store your board. This page says exactly what else it stores, why, who it shares it with, and how to get it deleted. It is written from the code, not from a template, and it is kept short enough to actually read.

Last checked against the code:

Who this covers

This policy covers the ViBo website at vibomaker.com (also reachable at vibo.lifeos.studio) and the same app when it is installed from an app store or run inside a desktop wallpaper. They are all one service talking to one server, so one policy covers them. ViBo is operated from Sydney, Australia, and handles personal information under the Australian Privacy Act 1988. If you are somewhere with stronger rules — the EU or UK, for instance — you have the rights described below as well.

What ViBo collects, and why

Everything on this list is something the app needs to do the thing you asked it to do. There is no separate marketing profile.

  • Your account. You sign in with Google. Google tells ViBo your name, email address, profile picture and a Google account ID, and ViBo stores those so it knows which boards are yours. ViBo also stores the sign-in tokens Google issues so you stay signed in. ViBo never sees or stores a password.
  • Your boards. The title, every card on it — text, images, links, embedded videos or music, numbers, notes, and the private back of a card if you wrote one — the background, and up to ten recent snapshots of the board so you can go back. Check-ins you write about a board (a mood, a note) are stored beside it and are never copied when a board is shared, published or duplicated.
  • Using it without an account. You can build one board without signing in. Your browser makes up a random device ID and the board is stored under that ID. No name, no email; if you clear the browser's storage the ID is gone and so is the way back to that board.
  • Images you add. Pictures you upload or paste are stored in a file store so the board can load them. Older boards may still hold images inside the board itself.
  • Social features you opt into. Friend links you send or accept, invite links you create, comments you leave on boards or templates, the feature you voted for on the roadmap, and points you earn for using the app.
  • Feedback. If you use the feedback page, the message and, if you give it, an email address to reply to.
  • How the app is being used. ViBo records a small number of product events — for example that a card was added by pasting, and whether it succeeded — so the people building it can see what works. These are content-free by construction: the event says an image was pasted, never what the image was. You are recorded as a one-way hash of your ID, not the ID itself. If you arrived through a link with campaign tags (utm_source and the like), those tags are kept in your browser and sent with these events so ViBo knows which channels bring people in.
  • Server logs. The hosting provider keeps ordinary request logs — your IP address, browser type and the pages you asked for — for a short time, for security and to diagnose faults.

Cookies and browser storage

ViBo sets the minimum it can get away with, and nothing for advertising.

  • A session cookie so you stay signed in, and a security cookie that stops other sites making requests as you.
  • A cookie remembering the language you picked, if you changed it.
  • In your browser's local storage: the device ID and campaign tags described above, a local copy of a guest board and its recent snapshots so a closed tab does not lose it, cards you have copied to paste elsewhere, and a note that you have already seen the welcome screen.
  • No advertising cookies, no third-party analytics scripts, no tracking pixels. If you look at the network requests the page makes, the only analytics you will find go to ViBo's own server.

What other people can see

Nothing, unless you choose to show it. A board is private to you until you do one of these things.

  • Share a link. A public share link shows the front of every card to anyone who has the link. The private back of a card is stripped on the server before the page is sent, so it is not merely hidden — it is not there. Share pages ask search engines not to index them.
  • Publish to the community. A published template shows the board and your display name to everyone browsing the community shelf, and other people can copy it into their own account.
  • Comment. Comments show your display name next to what you wrote.
  • Add a friend. Friends can see what the friend features show them and nothing else.

Who else handles your data

ViBo does not sell personal information and does not share it with advertisers. It does rely on a small number of providers to run, and some cards reach out to other services because that is what the card is.

  • Google, for sign-in. Google's own privacy policy governs what Google does with the fact that you signed in to ViBo.
  • Vercel, which hosts the website and runs the app's server code. Its servers are in the United States.
  • Supabase, which holds the database and the image store. The database is in Sydney, Australia.
  • The services behind embedded cards. If you put a YouTube video, a Spotify playlist, a Pinterest pin or a similar embed on a board, your browser loads it from that service directly, and that service sees the request under its own privacy policy — exactly as if you had visited it. ViBo does not control what those services do.
  • Link previews and picture search. When you paste a link, ViBo's server fetches that page once to make a preview card, and when you search for free stock photos, ViBo's server sends your search words to Wikimedia Commons. Your own address is not passed on in either case.

How long it is kept

Your boards and account stay as long as your account does. Deleting a board deletes it and its snapshots. Guest boards stay until the browser that owns the device ID clears it or the board is deleted. Feedback is kept until it has been dealt with. Product events are kept for analysis and only ever identify you by the hash described above.

When your account is deleted, your boards, their snapshots, your uploaded images, your check-ins, comments, friend links, invite and points are deleted with it. A template you published to the community is removed from the shelf; copies other people already made of it are theirs and are not touched.

Your choices and rights

You can ask ViBo, at any time and for free, to show you the personal information it holds about you, to correct it, to give you a copy of your boards, or to delete your account and everything under it. Requests are answered by a person, normally within thirty days, and there is no fee. If you are in the EU or UK you can also object to, or ask to restrict, a use of your data, and you can complain to your data protection authority. In Australia you can complain to the Office of the Australian Information Commissioner.

Children

ViBo is not aimed at children under thirteen and does not knowingly collect information from them. If you think a child has made an account, get in touch and it will be removed.

Security

Everything travels over HTTPS. Access to the database and file store needs keys that are held only on the servers that run the app, not in the app you download. No system is perfectly secure, and if a breach ever affects your data you will be told what happened and what was involved.

Changes to this page

When the app starts collecting something new, this page changes before the feature ships, and the date at the top changes with it. Material changes are announced in the changelog.

Getting in touch

For any of the requests above, or any question about this page, use the feedback page and say it is a privacy request. Include the email address you signed in with, so the right account can be found.