This Privacy Policy explains how Kilian Frederix(“we”, “us”) collects, uses, and protects your personal data when you use VibraFlow (the “Service”). We are the data controller for the purposes of the EU General Data Protection Regulation (GDPR).
1. Data we collect
- Account data — your email address and a securely hashed version of your password (we never store your password in plain text).
- Content you create — tasks, categories, todo columns, and related details you add to the Service.
- Technical data — a single essential session cookie used to keep you logged in (see “Cookies” below).
We do not use analytics or advertising trackers, and we do not sell your data to anyone.
2. How we use your data
We process your data solely to provide the Service: to authenticate you, store the content you create, and let you access it across sessions and devices.
3. Legal basis (GDPR)
We process your data on the basis of performance of a contract (providing the Service you signed up for). Where required, we rely on your consent, which you may withdraw at any time.
4. Cookies
VibraFlow uses a single essential cookie to keep you signed in. It is an httpOnly session cookie containing a random token — it cannot be read by JavaScript and holds no personal information. We use no tracking, analytics, or advertising cookies, so no cookie consent banner is required.
5. Where your data is stored
Your data is stored in a PostgreSQL database hosted by Neon in the EU (Frankfurt) region, and the Service is hosted on Vercel. These providers process data on our behalf under their respective data-processing agreements.
6. Data retention
We keep your data for as long as your account is active. When you delete your account, your personal data and content are removed. Expired login sessions are deleted automatically.
7. Your rights
Under the GDPR you have the right to access, correct, export, or delete your personal data, to restrict or object to its processing, and to withdraw consent. You may also lodge a complaint with your local data protection authority.
To exercise any of these rights, contact us at kilianfrederix@gmail.com.
8. Security
Passwords are hashed with bcrypt, sessions use random tokens stored only as hashes, cookies are httpOnly and secure in production, and all traffic is served over HTTPS. No system is perfectly secure, but we take reasonable measures to protect your data.
9. Children
The Service is not intended for anyone under the age of 16, and we do not knowingly collect data from children.
10. Changes to this policy
We may update this policy from time to time. Material changes will be reflected by the “Last updated” date above.
11. Contact
Questions about this policy or your data? Email kilianfrederix@gmail.com. This Service is operated from Belgium.
See also our Terms of Service.