Privacy / Data
Privacy Policy
This policy explains how VIBRA collects and uses information across its apps and websites, including storage, sync, and AI features.
- Last updated
- September 6, 2026
- Sections
- 12
Scope
This Privacy Policy applies to websites, apps, support channels, and related services provided by VIBRA, Inc.
If a specific product requires additional explanation, VIBRA may provide it in the app, App Store listing, support page, or other product-specific notice.
Information we collect
VIBRA may collect inquiry details, product names, device and browser information, usage information, error information, purchase-related information, and support-related information.
Depending on the features used, VIBRA processes content users enter or save, preferences and usage settings, notification information, and references to files on the device. Where user-selected preferences include health-related information, it is processed only as needed for the selected features.
For VIBRA Tasks, VIBRA may collect a stable app-install identifier, product interactions, coarse purchase outcomes, launch, sync, and operation timing, crash and diagnostic information, and session replays with text inputs masked for product improvement and issue investigation. After sign-in, this data may be associated with a stable VIBRA Account analytics identifier. Google Tasks content, Google task or list IDs, search terms, OAuth tokens, precise location, and attachment filenames are not sent to PostHog.
For VIBRA Cocktails, VIBRA may collect submitted catalog search terms, viewed public catalog IDs, selected public ingredient and filter IDs, an anonymous app-install identifier, product interactions, coarse Full Bar purchase outcomes, crash and diagnostic information, and session replays with text inputs masked for product improvement and issue investigation. Complete favorites and My Bar lists are stored on the device. Location analytics is disabled.
For VIBRA Beers, VIBRA may collect catalog search terms only when the user explicitly submits them, viewed public catalog IDs, selected public filter IDs, an anonymous app-install identifier, product interactions, coarse Full Passport purchase outcomes, and crash and diagnostic information for product improvement and issue investigation. Beer names, breweries, tasting notes, photos, OCR or Apple Foundation Models inputs and outputs, receipts, transaction IDs, and raw error messages are not sent to PostHog. Bookmarks, tasting records, and attached photos stay on the device, while session replays always mask text inputs and images. Location analytics is disabled.
How we use information
VIBRA uses information to provide services, verify users, respond to inquiries, investigate issues, improve quality, deliver notifications, confirm purchase status, prevent abuse, and comply with legal obligations.
VIBRA does not use user-entered content for advertising, credit decisions, sale to third parties, or purposes unrelated to the user-facing service.
Google Account and Google service connections
Some VIBRA products connect to Google Accounts or Google services only after the user grants permission. For example, VIBRA Tasks uses https://www.googleapis.com/auth/tasks so users can view, create, edit, complete, reopen, move, and delete their own Google Tasks.
Information obtained through Google connections is used only to provide user-facing features. VIBRA does not receive or store Google passwords.
Google Tasks content is processed only as needed for in-app display, editing, notifications, sharing, and recovery of pending edits.
VIBRA-owned metadata for app-only features may be handled in VIBRA Cloud with the Google task or list identifiers needed to attach it to the correct item. VIBRA Cloud does not store Google Tasks content or OAuth tokens.
Limited use of Google user data
VIBRA's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Google user data is not used for advertising, credit decisions, data sale, unrelated analytics, or AI model training.
Google user data is not shared, transferred, or disclosed to third parties except as needed to sync with the Google Tasks API, operate the service, provide support, address security issues, comply with law, or complete sharing explicitly chosen by the user.
VIBRA personnel access user-entered content obtained through Google connections only when the user explicitly shares it for support, when needed for security, when required by law, or with user consent.
Storage and handling
Information required to provide services may be stored on the user's device, in systems managed by VIBRA, or in third-party services used to provide the product.
Cloud backup and sharing are used when the user chooses the relevant feature. Storage and sharing scope depend on feature settings and account permissions. A personal backup may include information that is not shared with other users.
Google authorization information is stored in secure storage on the user's device and is used to connect to Google services, refresh the connection, and disconnect the connection.
Some information, such as attachments or images, may remain on the user's device. If cloud storage scope changes, VIBRA will update this policy or the relevant in-app notice.
Third-party services
VIBRA may use third-party services such as Google, Apple, Supabase, PowerSync, RevenueCat, PostHog, and OpenAI where needed to provide its services.
VIBRA Cloud sync uses Supabase and PowerSync for accounts, paid-feature access, sync state, and the content and settings users choose to store or sync. For Google Tasks connections, it processes VIBRA-owned metadata and the Google task or list identifiers needed to attach it to the correct item, but does not store Google Tasks content or OAuth tokens.
PostHog events are grouped with a stable app-install identifier so VIBRA can understand activity from the same installation. In products with account features, events may be associated with a stable VIBRA Account analytics identifier after sign-in. This association is used for product analytics and issue investigation, not advertising or tracking across other companies' apps or websites. Email addresses, App Store transaction IDs, receipts, and StoreKit verification payloads are not sent to PostHog.
For installs attributed to Apple Ads, VIBRA Tasks may process attribution data provided by Apple's AdServices through RevenueCat to measure campaign, ad group, and keyword performance against purchase outcomes. This does not collect the IDFA and is not used to track activity across other companies' apps or websites.
Analytics and diagnostics may include usage, screen interactions, crash and performance information, and session replays. Collection and masking follow the relevant product disclosures, with restrictions to avoid collecting unnecessary input content or authentication information.
Information sent to third-party services is limited to what is necessary for product functionality, purchase confirmation, issue investigation, notification delivery, and support. VIBRA does not use advertising tracking SDKs.
Cloud AI features
Cloud AI features show what will be sent and send the inputs, conditions, and candidate information needed for the feature to OpenAI through VIBRA servers only when the user chooses to submit them. Personal preference answers used solely to filter candidates on the device are not sent to OpenAI. This section does not apply to AI features that run entirely on the device.
Requests to OpenAI do not include account email addresses, user IDs, anonymous IDs, or authentication tokens. VIBRA servers use a user ID or anonymous ID, depending on sign-in state, to manage usage limits and prevent abuse. Signing in does not automatically merge earlier anonymous records into the account.
VIBRA stores AI submission conditions, prompts, responses, provided reasoning summaries, processing results, and usage on its servers without a fixed retention limit for quality review and improvement. Quality review is separate from AI model training; user content is not used for model training.
Disabling a feature, signing out, or uninstalling the app does not delete AI records. Requests to review or delete records can be made through support. Deleting an account may not delete records from anonymous use.
Retention and deletion
VIBRA retains information only for as long as needed for the purposes described in this policy or as required by law. Information that is no longer needed is deleted or anonymized where reasonably possible.
Stopping backup or signing out does not delete existing cloud data. Device data, cloud data, and shared copies follow their respective deletion controls and permissions. AI record retention and deletion follow the preceding section.
Google connections can be disconnected in the app or from the user's Google Account settings. After disconnection, VIBRA products do not make new requests to the connected Google service.
Users may contact support at https://vibra.jp/support to ask about data deletion or data handling.
Security
VIBRA applies reasonable safeguards, including access controls, protected communication, and permission management, to reduce the risk of unauthorized access, loss, alteration, or disclosure.
Changes to this policy
VIBRA may update this policy when its services, processed information, third-party services, laws, or review requirements change. Material changes will be communicated through the website or in-app notice where appropriate.
Contact
Questions about this policy or data handling can be sent through https://vibra.jp/support.