Privacy Policy
Last updated: August 5, 2026
VisionBoard (“we”, “us”, or “our”) is committed to protecting your personal information. This Privacy Policy explains what data we collect, how we use it, and your rights regarding that data when you use our platform at vision-board.tech (the “Service”).
1. Information We Collect
- Account information: name, email address, and profile picture provided during registration or OAuth sign-in.
- Workspace data: goals, milestones, sprints, tasks, board items, and documents you create within the Service.
- AI interaction data: prompts submitted to AI features (roadmap generator, goal deconstructor, natural language board editing) and the responses generated. These are stored in an AI generation log.
- Usage data: feature interactions, session durations, page views, and AI credit consumption.
- Billing data: subscription tier and billing history. Payment card details are handled exclusively by Stripe and are never stored on our servers.
- Communications: messages you send to our support team or feedback you submit.
2. How We Use Your Information
- Provision and maintain your account and workspaces.
- Process AI requests via OpenRouter API — all calls are made server-side; your data is never sent directly from your browser to OpenRouter or its underlying models.
- Send transactional emails (workspace invitations, password resets, billing receipts) via Resend.
- Process subscription payments and manage billing via Stripe.
- Detect and prevent fraud, abuse, and violations of our Terms of Service.
- Analyze aggregate usage patterns to improve product features.
3. Data Storage & Security
Your data is stored in a PostgreSQL database (hosted on Supabase or a compatible PostgreSQL provider) with PgBouncer connection pooling. All data is encrypted at rest and in transit via TLS 1.2+.
Additional security measures include:
- bcrypt hashing for passwords (minimum cost factor 12).
- HTTP-only, secure, SameSite session cookies.
- CSRF protection on all state-changing endpoints.
- Rate limiting on authentication and AI endpoints.
4. Third-Party Services
- OpenRouter — routes AI requests to the underlying language models powering roadmap generation, goal deconstruction, and natural language board editing. Prompts are transmitted server-side only; interaction logs are retained for 90 days.
- Stripe — handles all payment processing and subscription management. We store only your Stripe customer ID and subscription status; card details never touch our servers.
- Resend — delivers transactional emails (invitations, password resets, billing confirmations).
- Google OAuth — optional sign-in via your Google account. We receive only your name, email, and profile picture.
5. Cookies & Sessions
6. Data Retention
- Active accounts: data is retained for as long as your account remains active.
- Deleted accounts: personal data is permanently purged within 30 days of account deletion.
- AI generation logs: retained for 90 days for quality assurance and abuse monitoring, then permanently deleted.
- Billing records: retained for 7 years as required by applicable financial regulations.
7. Your Rights
- Access a copy of the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Request deletion of your account and all associated data.
- Export your workspace data in a portable format.
- Object to or restrict certain processing activities.
- Withdraw consent where processing is based on consent.
To exercise any of these rights, email privacy@vision-board.tech. We will respond within 30 days.
8. Children's Privacy
9. International Transfers
10. Changes to This Policy
11. Contact
For privacy-related questions, data access requests, or to report a concern, contact us at:
VisionBoard Inc.
Email: privacy@vision-board.tech