Vibtra
Privacy notice
This is a short-form notice. The full privacy policy is in preparation and will replace this page. Questions go to sam@vibtra.app.
Who we are
This service is provided by Vibtra, the operator of vibtra.app. Formal entity details will be stated in the full policy. Privacy questions, access requests and complaints go to sam@vibtra.app.
What we collect when you sign in
You sign in with Google, or with an identity provider your organisation has registered. From that provider we receive your email address, your name, your profile picture and your organisation's email domain. We never receive your password. When a session is created we also record your IP address and your browser's user agent.
What the console stores
The console keeps what your organisation puts into it: the people and groups in the organisation, the connections it has added, the tools it has deployed, one receipt per deploy, and an append-only audit ledger of who did what. A connection's credential is sealed before it is written and only the ciphertext is stored. The console does not store your tool's source code, and it does not read a row of business data from the systems you connect.
Where it is stored
The hosted registry runs in AWS ap-southeast-2 (Sydney). The database, its backups and the key that seals credentials stay in that region. Requests reach vibtra.app through Amazon CloudFront. Its edge locations store only the public build files under /landing/ and /assets/; this page, the landing page, sign-in, the console's API and the vault pass through the edge without being stored there.
What leaves the region, and why
- Google sign-in. The sign-in is exchanged with Google, which learns that you signed in.
- Deploying a tool. The composed tool and the environment it needs go to your own Vercel, Netlify or Cloudflare account, with the token your administrator added.
- Adding a deploy target. One request to that vendor, to check the token works.
- Testing a connection. The registry connects to the system you named, to check the credential and read the scopes it grants. It reads no business data.
- Email. Where the operator has set a mail key, a small set of transactional messages (invitations, decisions on access and package requests, and one reminder) is sent through Resend in the United States. Where it is unset, nothing is sent.
- Packages. Where your administrators have allowed npm packages, the exact versions they approved are fetched from the npm registry at deploy time, and a package search from the console asks the same registry.
- Your tool's own traffic. Goes from your tool to your systems, and never through Vibtra.
- The edge. Every request enters AWS at the CloudFront location nearest you and is carried to Sydney over AWS's own network.
What Vibtra does not do
We do not sell personal information. We do not use it for advertising. The registry does not call any AI model. This page loads no third-party fonts and no analytics.
How long we keep it
The audit ledger, the receipts and the vault's audit log are append-only. Nothing in the product can edit or delete a record in them, so they are kept for at least the life of your organisation's account. A sealed credential is destroyed when your administrator removes its connection. The full policy will state retention periods for everything else.
Your rights
Email sam@vibtra.app to ask what we hold about you, to have it corrected, or to object to how it is used. We will confirm your identity before we answer. Inside the console, your organisation's owner or an admin can remove people, remove groups and delete connections; deleting a connection destroys its sealed credential.
Changes
Changes to this notice are posted on this page with a new effective date. The formal privacy policy is in preparation and will replace this notice when it is published.