Legal

Privacy Policy

Last updated: August 5, 2026

VisionBoard (“we”, “us”, or “our”) is committed to protecting your personal information. This Privacy Policy explains what data we collect, how we use it, and your rights regarding that data when you use our platform at vision-board.tech (the “Service”).

1. Information We Collect

We collect information you provide directly, as well as data generated through your use of the Service:
  • Account information: name, email address, and profile picture provided during registration or OAuth sign-in.
  • Workspace data: goals, milestones, sprints, tasks, board items, and documents you create within the Service.
  • AI interaction data: prompts submitted to AI features (roadmap generator, goal deconstructor, natural language board editing) and the responses generated. These are stored in an AI generation log.
  • Usage data: feature interactions, session durations, page views, and AI credit consumption.
  • Billing data: subscription tier and billing history. Payment card details are handled exclusively by Stripe and are never stored on our servers.
  • Communications: messages you send to our support team or feedback you submit.

2. How We Use Your Information

We use your information solely to operate and improve the Service:
  • Provision and maintain your account and workspaces.
  • Process AI requests via OpenRouter API — all calls are made server-side; your data is never sent directly from your browser to OpenRouter or its underlying models.
  • Send transactional emails (workspace invitations, password resets, billing receipts) via Resend.
  • Process subscription payments and manage billing via Stripe.
  • Detect and prevent fraud, abuse, and violations of our Terms of Service.
  • Analyze aggregate usage patterns to improve product features.
We do not use your data for advertising and we do not sell your data to any third party.

3. Data Storage & Security

Your data is stored in a PostgreSQL database (hosted on Supabase or a compatible PostgreSQL provider) with PgBouncer connection pooling. All data is encrypted at rest and in transit via TLS 1.2+.

Additional security measures include:

  • bcrypt hashing for passwords (minimum cost factor 12).
  • HTTP-only, secure, SameSite session cookies.
  • CSRF protection on all state-changing endpoints.
  • Rate limiting on authentication and AI endpoints.

4. Third-Party Services

VisionBoard shares data with the following sub-processors solely to deliver the Service:
  • OpenRouter — routes AI requests to the underlying language models powering roadmap generation, goal deconstruction, and natural language board editing. Prompts are transmitted server-side only; interaction logs are retained for 90 days.
  • Stripe — handles all payment processing and subscription management. We store only your Stripe customer ID and subscription status; card details never touch our servers.
  • Resend — delivers transactional emails (invitations, password resets, billing confirmations).
  • Google OAuth — optional sign-in via your Google account. We receive only your name, email, and profile picture.
No other third parties have access to your personal data.

5. Cookies & Sessions

We use a single secure, HTTP-only session cookie (JWT-based via NextAuth.js) to maintain your authenticated session. This cookie is strictly necessary for the Service to function. We do not use advertising cookies, tracking pixels, or any third-party analytics scripts.

6. Data Retention

  • Active accounts: data is retained for as long as your account remains active.
  • Deleted accounts: personal data is permanently purged within 30 days of account deletion.
  • AI generation logs: retained for 90 days for quality assurance and abuse monitoring, then permanently deleted.
  • Billing records: retained for 7 years as required by applicable financial regulations.

7. Your Rights

Depending on your jurisdiction (including GDPR and CCPA), you may have the right to:
  • Access a copy of the personal data we hold about you.
  • Correct inaccurate or incomplete data.
  • Request deletion of your account and all associated data.
  • Export your workspace data in a portable format.
  • Object to or restrict certain processing activities.
  • Withdraw consent where processing is based on consent.

To exercise any of these rights, email privacy@vision-board.tech. We will respond within 30 days.

8. Children's Privacy

VisionBoard is intended for users aged 16 and older. We do not knowingly collect personal information from children under 16. If you believe a child has provided us with personal data, please contact privacy@vision-board.tech and we will promptly delete it.

9. International Transfers

VisionBoard operates from Nigeria. If you are accessing the Service from outside Nigeria, your data may be transferred to and processed in other countries where our sub-processors (including Stripe, Resend, OpenRouter, and Google) operate. We ensure appropriate safeguards are in place for such transfers, including Standard Contractual Clauses where required under applicable data protection law.

10. Changes to This Policy

We may update this Privacy Policy from time to time. For material changes, we will notify you by email or via an in-app notice at least 14 days before the changes take effect. The “Last updated” date at the top of this page always reflects the most recent revision.

11. Contact

For privacy-related questions, data access requests, or to report a concern, contact us at:

VisionBoard Inc.

Email: privacy@vision-board.tech