Guest drafts
A guest chart is device-local browser data. It stays separate from a company workspace unless you choose an account handoff.
PRIVACY & DATA HANDLING
Last updated July 23, 2026. The data path changes when you draft as a guest, sign in, import a source, join a workspace, share a chart, contact support, or—if enabled—manage a paid plan.
A guest chart is device-local browser data. It stays separate from a company workspace unless you choose an account handoff.
Supabase Auth supports email and Google sign-in. Saved charts, memberships, invitations, plan records, and sharing records use the configured workspace data service.
With explicit consent, a selected source is uploaded to Vibe My Org for transient, in-memory text and layout extraction. When external AI is enabled for the import, your prompt or that extracted evidence is sent to Google Gemini. Structured spreadsheets and eligible screenshots can be mapped locally without sending extracted content to the AI provider. Original uploaded file bytes and image pixels are not forwarded to the model or retained after the import request completes.
The Contact form sends your name, work email, selected topic, optional approximate team-size range, message, and consent value to Netlify Forms for support storage and follow-up. Do not include passwords, private chart contents, or other sensitive information in a support request.
A public share makes the selected chart readable to anyone holding an active link until it expires or an authorized member revokes it. The link does not grant editing rights or organization membership. Treat it as access to the chart and send it only to intended recipients.
Stripe handles card details for paid checkout and billing management. Payments use a Stripe account operated by Zero G Foundry LLC. Vibe My Org stores provider customer and subscription identifiers, the selected plan, subscription status, period and cancellation state, and limited event metadata for access reconciliation. It does not store full card numbers.
CURRENT NOTICE · 2026-07-22
This notice covers visitors, guest creators, account holders, invited and active workspace members, public-share viewers, and people who send a support request. It explains the current Vibe My Org product paths; it does not describe a capability merely because that capability is planned.
“We” means the operator of the Vibe My Org service at vibemyorg.com. No unapproved contracting entity or notice address is supplied here. When an organization controls a workspace, that organization also decides which people data its authorized members add, edit, share, or remove. Contact the workspace owner as well as Vibe My Org when a request concerns organization-controlled content.
Identity and access data. This includes the email and authentication information used to sign in, session information, organization membership, invitations, verified-domain eligibility, role, and legal-document acceptance records. Google supplies account information when you choose Google sign-in.
Chart and workspace data. This includes workspace and chart names; people names and titles; reporting relationships; chart ordering and saved state; member roles; share grants; and the content you choose to save, edit, export, or share. Another authorized member or workspace owner may provide information about you.
Creation and import data. This includes a natural-language prompt, the file you select, extracted structure, generated draft, warnings, and corrections you make. It also includes basic request records used to enforce import size, rate, and capacity limits and to diagnose a failed request.
Support, share, and plan data. This includes support form fields, public-share status and expiry, free save and export usage, and—only after public billing is enabled—the provider and subscription records described above. Browser and network request information is also transmitted when you load or use an online service.
On the canonical production site, a random session identifier and canonical page category can be recorded with an external referrer hostname, controlled campaign labels, a selected plan variant, and browser-reported Core Web Vitals. An authorized checkout also uses an internal checkout-attempt identifier solely to prevent duplicate conversion records. The same minimized lane can record completed chart saves, official exports, and share-link creation as event names only; it does not add chart, export-format, share-link, account, or workspace details. The funnel record does not accept query strings, chart or company names, employee names or email addresses, organization slugs, free-form metadata, advertising identifiers, or an account identifier. It uses no third-party advertising tracker or cross-site analytics cookie.
We use this information to authenticate people; verify membership; create and administer workspaces; save, edit, import, export, and share charts; enforce free allowances and builder access; operate a paid plan only when enabled; answer support requests; prevent abuse; investigate failures; protect users and workspaces; and maintain the service’s operational records.
The source of the information is usually you, an authorized workspace member, an invitation sender, your chosen sign-in provider, a share viewer’s request, or the service provider completing a feature you asked to use.
Workspace content is available to active members according to their role and the product’s authorization rules. A selected chart is also available to people with its active public link. Those recipients may copy what they can see, and Vibe My Org cannot remove a copy held outside the service.
Information may also be disclosed when required by applicable law or when reasonably necessary to protect people, workspaces, the service, or legal rights. This notice does not promise a disclosure that is not legally required.
A guest chart remains in that browser’s local storage until it is cleared, replaced, or the browser storage becomes unavailable. A source upload is not kept by this application after the import request, but the extracted or generated draft may remain locally or in a workspace if you save it.
Saved account and workspace information remains while the account or workspace uses the service and until it is deleted or a valid request is completed. Revoking or expiring a share stops future link access; an operational grant record or a recipient’s copy may remain. Support, security, usage, billing, and transaction records may be retained as needed for support, abuse prevention, reconciliation, disputes, and applicable legal obligations.
Privacy-minimized product-funnel event rows become eligible for deletion after 90 days and are removed in bounded cleanup runs. Service-only daily totals may remain without the session identifier or individual event rows. No shorter fixed retention schedule is promised here for the other operational records described above.
You can keep a draft only on your device, clear browser storage, decline an AI import, correct a chart, choose not to share, revoke an active share link, or stop using the service. Use the Contact form to request access, correction, or deletion of account or workspace information, or to object to or restrict processing where applicable law provides that right.
We may need to verify your identity and authority over organization-owned data. Some records may remain when required for security, transactions, disputes, or legal obligations. If you disagree with a response, reply through the same contact path and ask for another review; any additional rights under applicable law remain available. This notice does not promise a response deadline that has not been established.
The current product uses verified identity and active membership for company access, organization identifiers on tenant-owned records, database row-level authorization, bounded imports, and revocable read-only share links. A public link is still a credential: anyone holding it can view the shared chart while it remains active.
No online service can promise absolute security. Use approved data, limit membership, review links, and contact us if you suspect misuse. The configured providers may process information in countries other than your own under their own service terms and privacy notices. This notice does not claim a specific hosting region or transfer mechanism that has not been published.
Vibe My Org is a workplace organization-chart service and is not directed to children. Do not create an account for a child or upload information about children or minors. If you believe that information has been provided, use the Contact form so the request can be reviewed with the relevant workspace owner.
The current product does not implement cross-context behavioral advertising, an advertising profile, or a flow that sells chart, account, import, or support content for advertising. Because there is no advertising-tracking flow to change, Global Privacy Control and Do Not Track signals do not alter current product behavior. This notice must be updated before an advertising-data use is introduced.
AI assistance proposes a reviewable chart draft; it does not make a legal or similarly significant decision about employment, workspace membership, billing access, or any person. A user chooses whether to correct, save, export, or share the result.
A changed notice will show a new effective date. Account users may be asked to review and accept a new version before returning to a protected workspace. A change to the operator identity, paid checkout, advertising use, or a material data path must be reflected here before that change is represented as live.
For a privacy request or question, use the Contact form and choose the security or privacy topic. Do not place passwords or private chart contents in the message.