Legal
Privacy Policy
How VibePlan handles personal data for accounts, workspaces, and related services.
Last updated: 27 July 2026
1. Who we are
VibePlan is operated by the sole trader trading as VibePlan (also trading as ProcureLex and CommerceSans). For entity and registration status, see our internal record (ICO fee-payer registration in progress). Contact for privacy requests: use authenticated Help after sign-in, or the support email configured for your deployment when available.
We have assessed that a statutory Data Protection Officer is not required for our core activities (no large-scale behavioural monitoring; no large-scale special-category or criminal-offence processing as a core activity).
2. Roles
- Controller for account data (email, name, billing identity), product analytics, support tickets you open with us, and platform telemetry we decide the purposes for.
- Processor for customer workspace content (Discovery answers, blueprints, capabilities, deliverables, uploads, agent and connection configurations) that you and your members enter while using VibePlan. The workspace customer is the controller for that content. Our B2B Data Processing Agreement applies when you require a processor contract.
3. Categories of personal data
- Account and profile: email, name, authentication identifiers
- Billing: plan, invoices, payment tokens handled by Stripe
- Workspace content you provide (may incidentally include personal data)
- Usage and device/event data via PostHog (EU Cloud when configured)
- Support and Help chat messages you send to us
- Security and audit logs (activity, MCP, integration, run events)
4. Purposes and lawful bases (UK GDPR)
- Contract — provide the service, authenticate users, generate and store workspace artefacts, bill subscriptions.
- Legitimate interests — secure the service, prevent abuse, improve product analytics, internal audit trails (balanced against your rights).
- Legal obligation — tax and accounting records; respond to lawful requests.
5. AI processing
VibePlan uses AI to draft blueprints and related outputs. Humans review and approve meaningful actions. External provider writes are approval-gated by default. Outputs are not legal, financial, or medical advice. See Acceptable Use and our claims guidance for marketers and operators.
6. Subprocessors
Platform subprocessors (hosting, database, LLM routing, email, billing, analytics, workflows) are listed at /legal/subprocessors. LLM processing is primarily routed through OpenRouter with labeled OpenAI availability failover where configured.
7. Retention
We keep personal data only as long as needed for the purposes above, including legal and accounting duties. Current targets:
| Category | Retention |
|---|---|
| Account identity (email, name, auth identifiers) | Until account closure, then as needed for security or legal obligations |
| Workspace content (Discovery, blueprints, capabilities, deliverables, uploads, agents, Connections config) | Until you permanently delete the workspace (after archive); subject to short vendor backup windows |
| Document version history | Bounded by your plan's version-history depth |
| Evidence / provenance citations | With related document versions; pruned when versions are removed |
| Operational logs (activity, agent/run events, MCP audit) | Rolling 90 days (nightly prune); removed sooner if the workspace is deleted |
| AI usage events (model/token metadata) | Rolling 30 days (nightly prune); removed sooner if the workspace is deleted |
| MCP audit log views (Pro) | In-product query window aligns with the last 90 days |
| Billing and tax records | Up to 7 years where required (often held by Stripe) |
| Support / Help conversations | While needed to resolve your request and for security or abuse follow-up |
Permanent workspace delete removes related workspace rows in our database via cascading deletes. Some account-level records (for example support tickets or AI wallet ledger lines) may retain a null workspace reference. Residual copies may exist briefly in infrastructure backups.
8. Your rights
Under UK GDPR you may have rights of access, rectification, erasure, restriction, portability, and objection. You may complain to the Information Commissioner's Office.
- Portability / access (workspace): export blueprints as JSON or Markdown from the workspace card menu, Settings (Export & account data), Blueprints, and related download actions where your plan includes exports. Incomplete or unreviewed blueprints may be blocked by quality checks.
- Erasure (workspace): workspace owners can archive a workspace, then permanently delete it from the dashboard (name confirmation required). You must keep at least one workspace.
- Account closure and other requests: use authenticated Help (including Request account closure in Settings), or the support email configured for your deployment when available. A full one-click account archive is not yet offered; we will fulfil reasonable requests manually.
9. International transfers
Where subprocessors process data outside the UK, we rely on appropriate transfer tools (such as the UK IDTA or UK addendum to EU SCCs) as provided in vendor terms, or UK/EU adequacy where applicable.
10. Security
We use HTTPS, Supabase Auth and RLS, hashed secrets for MCP keys, approval gates for high-risk actions, and security headers. No security measure is perfect; report suspected incidents via Help.
11. Children
VibePlan is for business users and is not directed at children.
12. Changes
We may update this policy. The "Last updated" date above will change when we do. Material changes may be notified in-product or by email when practicable.
Draft for commercial launch. Legal review and sign-off are still required before treating these pages as final counsel-approved terms.