Skip to content
VibeAdmin

Privacy Policy

Last updated 2026-10-11

What we collect, why, who we share it with, and the choices you have.

1. Who this covers

This policy explains what personal data easy-admin.solutions ("we", "us") processes when you use VibeAdmin, and why. It covers two groups: the people who use our dashboard (our customers and their teams), and the end users of our customers' apps, whose data our customers connect to the service. For the second group, our customer decides why the data is processed and we act as their processor; if you are one of their users, please contact that app first.

2. What we process

  • Account data: your name, email address and password (stored hashed), or your name, email and profile picture if you sign in with Google. Your organization, team members and their roles.
  • Service activity: audit-log entries of what was done and by whom, with the IP address and browser details; API-key usage; basic server logs and rate-limit counters.
  • Customer Data you connect or send: the users of your app (identifiers, email, name, plan, status, custom fields you choose to sync), events and statistics, error reports (message, stack and the user id you attach; we remove obvious secrets and drop URL query strings), webhook payloads, and broadcast emails with their recipients and delivery status.
  • Credentials you give us for integrations, such as an API key for your auth provider, database or email provider. These are encrypted with a per-project key and are not shown again.
  • Billing data: for paid plans, Stripe handles your card and payment details. We keep your Stripe customer and subscription identifiers, plan and status. We do not receive your card number.
  • AI features: when you use them, the text you write and, for the assistant, your questions and the data its tools look up.

3. How we use it

Where the law requires a legal basis: we rely on performing our contract with you, our legitimate interests in running and securing the service, legal obligations, and your consent where we ask for it.

  • To provide the service: show and manage your users, run syncs, send the email you ask us to send, evaluate feature flags and respond to API calls.
  • To secure it: authenticate people, enforce permissions, rate-limit abuse, keep an audit trail and investigate incidents.
  • To bill you and to contact you about your account, security and important changes.
  • To improve reliability and fix bugs. We do not sell personal data, we do not use Customer Data for advertising, and we do not use it to train AI models.

4. Who we share it with

We share data only with the providers that help us run the service, and only as needed:

  • Stripe, to take payments.
  • Our AI provider (currently Anthropic), only when you use the AI email or assistant features. The assistant is off until you enable it for a project.
  • The email provider you connect, to send the email you tell us to send.
  • The auth, database and payment systems you connect: we read from and, if you allow it, write to them on your instructions.
  • Our hosting and infrastructure providers, who store and process data for us.
  • Authorities, where the law requires it, and a successor if the business is transferred (we will tell you).

5. Cookies

The dashboard uses a session cookie that keeps you signed in. It is strictly necessary, expires with your session, and is not used for tracking. The public website does not use advertising or analytics cookies.

6. How we protect it

Connections use TLS. Integration credentials are encrypted at rest per project, API keys and passwords are stored hashed, access is controlled by roles and scoped keys, environments are isolated, and actions are recorded in an append-only audit log. No system is perfectly secure; if a breach affects your data, we will notify you as the law requires. More detail is on our security page.

7. How long we keep it

We keep account and Customer Data while your account is active. Error occurrences are trimmed to the most recent ones per error. When your account ends, or when you ask us to, we delete your data within a reasonable time, except records we must keep by law (for example billing records) and short-lived backups. You can also delete users and data from the dashboard and the API at any time.

8. Where it is processed

We and our providers may process data in countries other than your own. Where that involves moving personal data out of the EEA, UK or Switzerland, we rely on appropriate safeguards such as standard contractual clauses.

9. Your rights

Depending on where you live, you may have the right to access, correct, delete or export your personal data, to object to or restrict how it is used, to withdraw consent, and to complain to your data protection authority. You can do much of this in the dashboard. For anything else, contact us. If your data is in a customer's app, we will help that customer respond to your request, and we may direct you to them.

10. Children

VibeAdmin is for businesses and developers and is not directed at children under 16. We do not knowingly collect their data for our own purposes.

11. Changes

We may update this policy. We will tell you about material changes before they take effect, and the date at the top shows the latest version.

12. Contact

For privacy questions or requests, email us at support@webarm24.online.